DIRAS TAKE
Urgent: exploitability is higher because the flaw requires no privileges or user interaction (PR:N, UI:N). Apply the vendor updates immediately to remove exposed attack surface.
What is CVE-2026-64772?
A remote attacker can trigger an out-of-bounds write that may lead to code execution or crashes in Apple iOS and iPadOS (CVE-2026-64772). The issue affects iOS and iPadOS 18.x versions before 18.7.10 and 26.x versions before 26.6; related fixes are available for macOS, tvOS, and visionOS. The flaw can be exploited over a network and does not require user interaction or privileges. The weakness is classified as CWE-787 (Out-of-bounds Write).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple iOS and iPadOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 18.x | before 18.7.10 | 18.7.10 |
| iOS and iPadOS 26.x | before 26.6 | 26.6 |
| macOS 15.x | before 15.7.8 | 15.7.8 |
| macOS 26.x | before 26.6 | 26.6 |
| tvOS 26.x | before 26.6 | 26.6 |
| visionOS 26.x | before 26.6 | 26.6 |
Is CVE-2026-64772 being exploited?
There are no public reports of active exploitation as of 2026-09-29.
How to fix CVE-2026-64772
- Install Apple updates that contain the fixes — update iOS/iPadOS to 18.7.10 or 26.6 as applicable and macOS to 15.7.8 or 26.6, and update tvOS and visionOS to 26.6.
- If immediate updating is not possible, restrict network exposure of devices and services that could be reached by untrusted networks.
- Monitor device logs and intrusion-detection systems for unusual crashes or signs of heap corruption and follow Apple's guidance for incident handling.
Frequently asked questions
Is CVE-2026-64772 being actively exploited?
There are no public reports of active exploitation of CVE-2026-64772 as of 2026-09-29.
Which iOS and iPadOS versions are affected by CVE-2026-64772?
iOS and iPadOS 18.x before 18.7.10 and 26.x before 26.6 are affected; related Apple platforms also have listed affected versions.
Is there a patch for CVE-2026-64772?
Yes. Apple released fixes: iOS and iPadOS 18.7.10 and 26.6, macOS 15.7.8 and 26.6, and tvOS and visionOS 26.6.
Does CVE-2026-64772 require authentication?
No. The vulnerability can be triggered without authentication or user interaction.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64772
- cve.org/CVERecord?id=CVE-2026-64772
- support.apple.com/en-us/128066
- support.apple.com/en-us/128067
- support.apple.com/en-us/128069
- support.apple.com/en-us/128070
- support.apple.com/en-us/128071
- support.apple.com/en-us/148287
- All Apple CVEs on CVE Radar
- CVEs published in September 2026