DIRAS TAKE
Treat this as high priority and apply Apple’s updates now: fixed builds are available for iOS/iPadOS 18.7.10 and 26.6 and for several macOS, tvOS and visionOS releases; patch internet-facing and high-value devices first.
What is CVE-2026-64774?
Remote attackers can trigger an integer overflow in Apple mobile operating systems to crash apps or corrupt heap memory; this issue is tracked as CVE-2026-64774. Affected releases include iOS and iPadOS before 18.7.10 and before 26.6, plus several macOS, tvOS and visionOS branches listed in vendor advisories. The vendor’s notes indicate the flaw can be reached remotely and do not require special privileges or user interaction to cause the problematic behavior, so network-accessible devices are at risk.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple iOS and iPadOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 18.x | before 18.7.10 | 18.7.10 |
| iOS and iPadOS 26.x | before 26.6 | 26.6 |
| macOS 14.x | before 14.8.8 | 14.8.8 |
| macOS 15.x | before 15.7.8 | 15.7.8 |
| macOS 26.x | before 26.6 | 26.6 |
| tvOS 26.x | before 26.6 | 26.6 |
| visionOS 26.x | before 26.6 | 26.6 |
Is CVE-2026-64774 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-64774
- Install iOS/iPadOS 18.7.10 or 26.6 (or later) on mobile devices.
- Apply the applicable macOS updates: 14.8.8, 15.7.8, or 26.6.
- Upgrade tvOS and visionOS devices to 26.6 (or later).
- If immediate patching is not possible, restrict network exposure of affected devices and monitor for crashes or unusual application behavior.
Frequently asked questions
Is CVE-2026-64774 being actively exploited?
There are no public reports of active exploitation of CVE-2026-64774 as of 2026-09-29.
Which iOS and iPadOS versions are affected by CVE-2026-64774?
Apple indicates devices running versions before iOS/iPadOS 18.7.10 and before 26.6 are affected; update to the fixed releases to remediate the issue.
Is there a patch for CVE-2026-64774?
Yes. Apple published fixes: iOS and iPadOS 18.7.10 and 26.6, and corresponding updates for macOS (14.8.8, 15.7.8, 26.6), tvOS 26.6 and visionOS 26.6.
What can an attacker do with CVE-2026-64774?
Exploitation can cause applications to terminate unexpectedly or produce heap corruption on affected Apple platforms, which may enable further compromise depending on the target and context.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64774
- cve.org/CVERecord?id=CVE-2026-64774
- support.apple.com/en-us/128066
- support.apple.com/en-us/128067
- support.apple.com/en-us/128069
- support.apple.com/en-us/128070
- support.apple.com/en-us/128071
- support.apple.com/en-us/128072
- support.apple.com/en-us/148287
- All Apple CVEs on CVE Radar
- CVEs published in September 2026