• PATCH AVAILABLE

CVE-2026-64775: pre-auth remote code execution in Apple iOS and iPadOS

Remote attackers can execute code and fully compromise iOS and iPadOS devices via a memory initialization vulnerability (CVE-2026-64775). Affected releases include iOS and iPadOS before 26.6; other Apple platforms listed include macOS 14.x before 14.8.8, macOS 15.x before 15.7.8, and several 26.x branches of macOS, tvOS, visionOS, and watchOS. The vulnerability requires network access and needs no user interaction or credentials to exploit.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00665
CWE
CWE-665
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is exploitable without authentication or user interaction, so apply vendor updates immediately to eliminate remote code execution risk.

What is CVE-2026-64775?

Remote attackers can execute code and fully compromise iOS and iPadOS devices via a memory initialization vulnerability (CVE-2026-64775). Affected releases include iOS and iPadOS before 26.6; other Apple platforms listed include macOS 14.x before 14.8.8, macOS 15.x before 15.7.8, and several 26.x branches of macOS, tvOS, visionOS, and watchOS. The vulnerability requires network access and needs no user interaction or credentials to exploit.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 26.xbefore 26.626.6
macOS 14.xbefore 14.8.814.8.8
macOS 15.xbefore 15.7.815.7.8
macOS 26.xbefore 26.626.6
tvOS 26.xbefore 26.626.6
visionOS 26.xbefore 26.626.6
watchOS 26.xbefore 26.626.6

Is CVE-2026-64775 being exploited?

There are no public reports of active exploitation as of 2026-09-29.

How to fix CVE-2026-64775

  1. Install the vendor fixes: update iOS and iPadOS to 26.6 and macOS, tvOS, visionOS, watchOS to the listed fixed releases.
  2. If immediate patching is not possible, restrict network exposure of affected devices and services to trusted networks only.
  3. Monitor device logs and network telemetry for unusual crashes or unexpected system terminations.
  4. Follow Apple's security guidance and apply updates from Apple as soon as they are available to your fleet.

Frequently asked questions

Is CVE-2026-64775 being actively exploited?

There are no public reports of exploitation of CVE-2026-64775 as of 2026-09-29.

Which iOS and iPadOS versions are affected by CVE-2026-64775?

iOS and iPadOS releases before 26.6 are affected; related Apple platforms and branches are listed in the vendor advisory.

Is there a patch for CVE-2026-64775?

Yes; Apple released fixes including iOS and iPadOS 26.6 and the stated fixed versions for macOS, tvOS, visionOS, and watchOS.

Does CVE-2026-64775 require authentication?

No; the vulnerability can be exploited without authentication or user interaction against affected Apple platforms.

References