Executive brief
iOS and related Apple operating systems contain a race condition in kernel memory handling that can allow malicious apps to cause unexpected system crashes or corrupt kernel memory. This vulnerability could lead to system instability, data corruption, or potentially enable further exploits that access sensitive system resources.
Technical details
A race condition vulnerability was identified in kernel-level state handling across Apple's operating systems. The vulnerability allows a local attacker (via a malicious app) to exploit timing windows in state management, potentially causing unexpected system termination or kernel memory corruption. The issue affects iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Apple addressed this with improved state handling in iOS 18.7.10, iPadOS 18.7.10, and the 26.6 releases of iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS. No public exploits in the wild have been reported.
Affected products
- Apple iOS before 18.7.10 and before 26.6
- Apple iPadOS before 18.7.10 and before 26.6
- Apple macOS Sequoia before 15.7.8
- Apple macOS Tahoe before 26.6
- Apple tvOS before 26.6
- Apple visionOS before 26.6
- Apple watchOS before 26.6
Timeline
- 2026-09-14: disclosed: CVE-2026-64717 published
- 2026-07-27: patched: iOS/iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6 released