Junglewise Threat Intelligence

CVE-2026-64736: Apple iOS and iPadOS out-of-bounds access in IOMobileFrameBuffer

CVE-2026-64736 · Severity: high · CVSS 7.1 · Published 2026-09-14

Technologies: Apple iPadOS. Vendors: Apple.

Executive brief

iOS and iPadOS contain an out-of-bounds memory access vulnerability in the IOMobileFrameBuffer component, which handles graphics memory management on iPhones and iPads. A malicious app could trigger this flaw to crash the device unexpectedly or corrupt critical kernel memory, potentially compromising system stability and security.

Technical details

An out-of-bounds access vulnerability exists in IOMobileFrameBuffer, addressed through improved bounds checking. The vulnerability is triggered when an app accesses memory beyond allocated buffers without proper validation. An attacker with local app execution capability can cause unexpected system termination or corrupt kernel memory. The vulnerability affects iOS 26.6.1 and earlier, and iPadOS 26.6.1 and earlier (iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Air 3rd generation and later, and other supported models). Fixes are available in iOS 26.6.1, iPadOS 26.6.1, and corresponding later versions.

Affected products

  • Apple iOS before 26.6.1
  • Apple iPadOS before 26.6.1

Timeline

  • 2026-09-14: disclosed: Advisory published and CVE-2026-64736 disclosed
  • 2026-08-17: patched: Patches released in iOS 26.6.1, iPadOS 26.6.1, and corresponding macOS versions

References

Related threats