AppleCVE-2026-64732
Apple iOS and iPadOS: improper access control
Medium4.6CVE-2026-64732 · Published Jul 27, 2026 · updated Aug 25, 2026
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7. An attacker with physical access may be able to access sensitive user data during iPhone Mirroring.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| iOS and iPadOS Product | < 18.7.10 | 18.7.10 |
| < 26.6 | 26.6 | |
| macOS Product | < 15.7.7 | 15.7.7 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-284
More Apple advisories
All Apple| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 27 | Apple iOS and iPadOS: out-of-bounds write | Critical9.8 | 18.7.10+3 more |
| Jul 27 | Apple iOS and iPadOS: out-of-bounds write | Critical9.8 | 18.7.10+3 more |
| Jul 27 | Apple iOS and iPadOS: buffer overflow | Critical9.8 | 18.7.10+2 more |
| Jul 27 | Apple iOS and iPadOS: out-of-bounds write | Critical9.8 | 18.7.10+2 more |
| Jul 27 | Apple iOS and iPadOS: integer overflow | Critical9.8 | 18.7.10+3 more |
| Jul 27 | A memory initialization issue was addressed with improved memory handling | Critical9.8 | 26.6+2 more |