• PATCH AVAILABLE

CVE-2026-64769: pre-auth remote code execution in Apple iOS and iPadOS

Remote attackers can trigger an out-of-bounds write that may lead to remote code execution or heap corruption on Apple iOS and iPadOS (CVE-2026-64769). Affected releases include iOS and iPadOS before 18.7.10 and before 26.6; related fixes were also released for macOS (14.8.8, 15.7.8, 26.6), tvOS 26.6 and visionOS 26.6. The flaw is exploitable over the network without authentication or user interaction, per the supplied CVSS vector, meaning an attacker only needs network access to reach a vulnerable device.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00801
CWE
CWE-787
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent — this is a network-accessible, unauthenticated vulnerability that can result in remote code execution; apply the vendor fixes immediately to exposed devices (no login or user action required).

What is CVE-2026-64769?

Remote attackers can trigger an out-of-bounds write that may lead to remote code execution or heap corruption on Apple iOS and iPadOS (CVE-2026-64769). Affected releases include iOS and iPadOS before 18.7.10 and before 26.6; related fixes were also released for macOS (14.8.8, 15.7.8, 26.6), tvOS 26.6 and visionOS 26.6. The flaw is exploitable over the network without authentication or user interaction, per the supplied CVSS vector, meaning an attacker only needs network access to reach a vulnerable device. The weakness is classified as CWE-787 (Out-of-bounds Write).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 18.xbefore 18.7.1018.7.10
iOS and iPadOS 26.xbefore 26.626.6
macOS 14.xbefore 14.8.814.8.8
macOS 15.xbefore 15.7.815.7.8
macOS 26.xbefore 26.626.6
tvOS 26.xbefore 26.626.6
visionOS 26.xbefore 26.626.6

Is CVE-2026-64769 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-64769

  1. Install the vendor updates: iOS/iPadOS 18.7.10 or later and 26.6 or later; macOS 14.8.8, 15.7.8 or 26.6; tvOS 26.6; visionOS 26.6.
  2. Restrict network exposure of affected devices and services until patches are applied (block or limit inbound access from untrusted networks).
  3. Monitor device and network logs for signs of crashes, unexpected reboots, or anomalous process behavior and follow vendor guidance for incident response.

Frequently asked questions

Is CVE-2026-64769 being actively exploited?

There are no public reports of active exploitation of CVE-2026-64769 as of 2026-09-29.

Which iOS and iPadOS versions are affected by CVE-2026-64769?

iOS and iPadOS releases before 18.7.10 and before 26.6 are affected; Apple also published fixes for related macOS, tvOS and visionOS branches.

Is there a patch for CVE-2026-64769?

Yes. Apple released fixes: iOS/iPadOS 18.7.10 and 26.6, macOS 14.8.8, 15.7.8 and 26.6, tvOS 26.6 and visionOS 26.6; apply the appropriate update for your devices.

Does CVE-2026-64769 require authentication?

No. The vulnerability can be triggered remotely without authentication or user interaction according to the supplied CVSS vector.

References