• PATCH AVAILABLE

CVE-2026-64771: remote code execution in Apple iOS and iPadOS

A remote attacker can execute code or crash devices running iOS, iPadOS and other Apple platforms by exploiting a buffer overflow (CVE-2026-64771). Affected releases include iOS and iPadOS 18.x before 18.7.10 and 26.x before 26.6; related macOS, tvOS and visionOS releases listed as before their respective 15.7.8 or 26.6 fixes are also affected. The vulnerability is exploitable remotely without authentication or user interaction according to the published CVSS vector, meaning an attacker only needs network access to target vulnerable devices.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00847
CWE
CWE-119
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Patch immediately: the flaw is remotely exploitable without authentication or user interaction, and vendor fixes are available for the affected branches.

What is CVE-2026-64771?

A remote attacker can execute code or crash devices running iOS, iPadOS and other Apple platforms by exploiting a buffer overflow (CVE-2026-64771). Affected releases include iOS and iPadOS 18.x before 18.7.10 and 26.x before 26.6; related macOS, tvOS and visionOS releases listed as before their respective 15.7.8 or 26.6 fixes are also affected. The vulnerability is exploitable remotely without authentication or user interaction according to the published CVSS vector, meaning an attacker only needs network access to target vulnerable devices.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 18.xbefore 18.7.1018.7.10
iOS and iPadOS 26.xbefore 26.626.6
macOS 15.xbefore 15.7.815.7.8
macOS 26.xbefore 26.626.6
tvOS 26.xbefore 26.626.6
visionOS 26.xbefore 26.626.6

Is CVE-2026-64771 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-64771

  1. Apply the vendor updates that contain the fixes: upgrade iOS/iPadOS to 18.7.10 or 26.6 and upgrade affected macOS, tvOS, and visionOS releases to the listed fixed versions.
  2. If immediate patching is not possible, restrict network exposure of vulnerable devices and services to trusted networks only.
  3. Monitor device logs and network traffic for signs of exploitation and unusual crashes or heap corruption.
  4. Follow Apple security guidance and test updates in your environment before broad deployment.

Frequently asked questions

Is CVE-2026-64771 being actively exploited?

There are no public reports of active exploitation of CVE-2026-64771 as of 2026-09-29.

Which iOS and iPadOS versions are affected by CVE-2026-64771?

iOS and iPadOS releases before 18.7.10 on the 18.x branch and before 26.6 on the 26.x branch are listed as affected.

Is there a patch for CVE-2026-64771?

Yes. Apple lists fixes in iOS and iPadOS 18.7.10 and 26.6; corresponding fixes are also provided for macOS 15.7.8, macOS 26.6, tvOS 26.6, and visionOS 26.6.

Does CVE-2026-64771 require authentication?

No. The vulnerability is reported as exploitable without authentication or user interaction, so an attacker only needs network access to target vulnerable devices.

References