DIRAS TAKE
Urgent: this is exploitable without authentication or user interaction, so apply vendor updates immediately to eliminate remote code execution risk.
What is CVE-2026-64775?
Remote attackers can execute code and fully compromise iOS and iPadOS devices via a memory initialization vulnerability (CVE-2026-64775). Affected releases include iOS and iPadOS before 26.6; other Apple platforms listed include macOS 14.x before 14.8.8, macOS 15.x before 15.7.8, and several 26.x branches of macOS, tvOS, visionOS, and watchOS. The vulnerability requires network access and needs no user interaction or credentials to exploit.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple iOS and iPadOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 26.x | before 26.6 | 26.6 |
| macOS 14.x | before 14.8.8 | 14.8.8 |
| macOS 15.x | before 15.7.8 | 15.7.8 |
| macOS 26.x | before 26.6 | 26.6 |
| tvOS 26.x | before 26.6 | 26.6 |
| visionOS 26.x | before 26.6 | 26.6 |
| watchOS 26.x | before 26.6 | 26.6 |
Is CVE-2026-64775 being exploited?
There are no public reports of active exploitation as of 2026-09-29.
How to fix CVE-2026-64775
- Install the vendor fixes: update iOS and iPadOS to 26.6 and macOS, tvOS, visionOS, watchOS to the listed fixed releases.
- If immediate patching is not possible, restrict network exposure of affected devices and services to trusted networks only.
- Monitor device logs and network telemetry for unusual crashes or unexpected system terminations.
- Follow Apple's security guidance and apply updates from Apple as soon as they are available to your fleet.
Frequently asked questions
Is CVE-2026-64775 being actively exploited?
There are no public reports of exploitation of CVE-2026-64775 as of 2026-09-29.
Which iOS and iPadOS versions are affected by CVE-2026-64775?
iOS and iPadOS releases before 26.6 are affected; related Apple platforms and branches are listed in the vendor advisory.
Is there a patch for CVE-2026-64775?
Yes; Apple released fixes including iOS and iPadOS 26.6 and the stated fixed versions for macOS, tvOS, visionOS, and watchOS.
Does CVE-2026-64775 require authentication?
No; the vulnerability can be exploited without authentication or user interaction against affected Apple platforms.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64775
- cve.org/CVERecord?id=CVE-2026-64775
- support.apple.com/en-us/128066
- support.apple.com/en-us/128067
- support.apple.com/en-us/128068
- support.apple.com/en-us/128069
- support.apple.com/en-us/128070
- support.apple.com/en-us/128071
- support.apple.com/en-us/128072
- All Apple CVEs on CVE Radar
- CVEs published in September 2026