DIRAS TAKE
Treat this as high priority: the vulnerability scores 9.8 and is reachable remotely without privileges or user interaction, so apply the vendor fixes promptly to internet-exposed devices.
What is CVE-2026-64770?
A remote attacker can trigger an out-of-bounds write against iOS and iPadOS, potentially causing heap corruption or application termination; this is tracked as CVE-2026-64770. Affected releases include iOS and iPadOS before 18.7.10 and before 26.6; other Apple platforms listed below are also affected. The CVSS vector indicates the issue can be reached over the network with no privileges and no user interaction required, so an attacker does not need an account or user action to attempt exploitation. The weakness is classified as CWE-787 (Out-of-bounds Write).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple iOS and iPadOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 18.x | before 18.7.10 | 18.7.10 |
| iOS and iPadOS 26.x | before 26.6 | 26.6 |
| macOS 14.x | before 14.8.8 | 14.8.8 |
| macOS 15.x | before 15.7.8 | 15.7.8 |
| macOS 26.x | before 26.6 | 26.6 |
| tvOS 26.x | before 26.6 | 26.6 |
| visionOS 26.x | before 26.6 | 26.6 |
Is CVE-2026-64770 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-64770
- Install the vendor fixes: update iOS and iPadOS to 18.7.10 or 26.6 as applicable.
- Update macOS to 14.8.8, 15.7.8, or 26.6 where listed, and update tvOS and visionOS to 26.6.
- Restrict network exposure of affected devices and services until patched.
- Monitor device logs and intrusion detection for crashes or signs of heap corruption and follow vendor guidance for additional mitigations.
Frequently asked questions
Is CVE-2026-64770 being actively exploited?
There are no public reports of exploitation as of 2026-09-29.
Which iOS and iPadOS versions are affected by CVE-2026-64770?
iOS and iPadOS releases before 18.7.10 and before 26.6 are listed as affected.
Is there a patch for CVE-2026-64770?
Yes; Apple published fixes including iOS and iPadOS 18.7.10 and 26.6 and corresponding updates for macOS, tvOS, and visionOS.
Does CVE-2026-64770 require authentication?
No; the reported CVSS vector shows no privileges and no user interaction are required to reach the vulnerability.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64770
- cve.org/CVERecord?id=CVE-2026-64770
- support.apple.com/en-us/128066
- support.apple.com/en-us/128067
- support.apple.com/en-us/128069
- support.apple.com/en-us/128070
- support.apple.com/en-us/128071
- support.apple.com/en-us/128072
- support.apple.com/en-us/148287
- All Apple CVEs on CVE Radar
- CVEs published in September 2026