• PATCH AVAILABLE

CVE-2026-64772: pre-auth remote code execution in Apple iOS and iPadOS

A remote attacker can trigger an out-of-bounds write that may lead to code execution or crashes in Apple iOS and iPadOS (CVE-2026-64772). The issue affects iOS and iPadOS 18.x versions before 18.7.10 and 26.x versions before 26.6; related fixes are available for macOS, tvOS, and visionOS. The flaw can be exploited over a network and does not require user interaction or privileges.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00783
CWE
CWE-787
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: exploitability is higher because the flaw requires no privileges or user interaction (PR:N, UI:N). Apply the vendor updates immediately to remove exposed attack surface.

What is CVE-2026-64772?

A remote attacker can trigger an out-of-bounds write that may lead to code execution or crashes in Apple iOS and iPadOS (CVE-2026-64772). The issue affects iOS and iPadOS 18.x versions before 18.7.10 and 26.x versions before 26.6; related fixes are available for macOS, tvOS, and visionOS. The flaw can be exploited over a network and does not require user interaction or privileges. The weakness is classified as CWE-787 (Out-of-bounds Write).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 18.xbefore 18.7.1018.7.10
iOS and iPadOS 26.xbefore 26.626.6
macOS 15.xbefore 15.7.815.7.8
macOS 26.xbefore 26.626.6
tvOS 26.xbefore 26.626.6
visionOS 26.xbefore 26.626.6

Is CVE-2026-64772 being exploited?

There are no public reports of active exploitation as of 2026-09-29.

How to fix CVE-2026-64772

  1. Install Apple updates that contain the fixes — update iOS/iPadOS to 18.7.10 or 26.6 as applicable and macOS to 15.7.8 or 26.6, and update tvOS and visionOS to 26.6.
  2. If immediate updating is not possible, restrict network exposure of devices and services that could be reached by untrusted networks.
  3. Monitor device logs and intrusion-detection systems for unusual crashes or signs of heap corruption and follow Apple's guidance for incident handling.

Frequently asked questions

Is CVE-2026-64772 being actively exploited?

There are no public reports of active exploitation of CVE-2026-64772 as of 2026-09-29.

Which iOS and iPadOS versions are affected by CVE-2026-64772?

iOS and iPadOS 18.x before 18.7.10 and 26.x before 26.6 are affected; related Apple platforms also have listed affected versions.

Is there a patch for CVE-2026-64772?

Yes. Apple released fixes: iOS and iPadOS 18.7.10 and 26.6, macOS 15.7.8 and 26.6, and tvOS and visionOS 26.6.

Does CVE-2026-64772 require authentication?

No. The vulnerability can be triggered without authentication or user interaction.

References