Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-64724

CVE-2026-64724: Apple iPadOS DoS Vulnerability

CVE-2026-64724 is a denial-of-service vulnerability in Apple iPadOS caused by improper memory handling. Local network attackers can trigger system crashes. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-64724 Overview

CVE-2026-64724 is a denial-of-service vulnerability affecting multiple Apple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The flaw stems from improper memory handling and can be triggered by an attacker on the local network. Apple resolved the issue by improving memory handling in the affected components. Successful exploitation causes the target device to become unresponsive, resulting in service disruption. The vulnerability is categorized under [CWE-400] Uncontrolled Resource Consumption. The attack requires user interaction and does not compromise confidentiality or integrity.

Critical Impact

An attacker on the local network can trigger a denial-of-service condition on affected Apple devices, disrupting availability across iOS, macOS, tvOS, visionOS, and watchOS platforms.

Affected Products

  • Apple iOS 26.6 and iPadOS 26.6 (prior versions)
  • Apple macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6 (prior versions)
  • Apple tvOS 26.6, visionOS 26.6, and watchOS 26.6 (prior versions)

Discovery Timeline

  • 2026-07-27 - CVE-2026-64724 published to the National Vulnerability Database (NVD)
  • 2026-07-28 - Last updated in NVD database

Technical Details for CVE-2026-64724

Vulnerability Analysis

CVE-2026-64724 is a memory handling defect that leads to uncontrolled resource consumption on affected Apple operating systems. When a specially crafted input reaches the vulnerable component over the local network, the flaw disrupts normal memory management. This condition renders the system unable to service legitimate requests, causing a denial-of-service state. Apple's advisories describe the fix as improved memory handling, indicating the pre-patch code path failed to enforce proper bounds or lifecycle management on memory resources. Exploitation requires user interaction, which limits opportunistic exploitation but remains feasible in shared network environments such as corporate LANs, conference Wi-Fi, or public hotspots.

Root Cause

The root cause is improper memory handling within a component shared across Apple's operating system family. The weakness maps to [CWE-400] Uncontrolled Resource Consumption. Insufficient validation or lifecycle management of memory objects allows an attacker-supplied input to exhaust or corrupt resources, terminating or hanging the affected service.

Attack Vector

Exploitation requires the attacker to be adjacent to the victim on the local network. The attacker must induce a user action to process the malicious input. Because the vulnerability spans iOS, iPadOS, macOS, tvOS, visionOS, and watchOS, any Apple device joined to a shared segment is a potential target. Refer to the Apple Security Advisory #128066 and related advisories for platform-specific technical details.

No verified public proof-of-concept code is available for CVE-2026-64724. Apple has not published exploitation specifics beyond the memory handling description in its security notes.

Detection Methods for CVE-2026-64724

Indicators of Compromise

  • Unexpected crashes, kernel panics, or system hangs on Apple devices immediately after joining a new network segment.
  • Recurring service restarts or watchdog resets logged in device diagnostics following exposure to untrusted local networks.
  • Abnormal spikes in memory pressure telemetry preceding process termination on macOS endpoints.

Detection Strategies

  • Collect and review crash reports from ~/Library/Logs/DiagnosticReports/ on macOS and mobile device diagnostic exports for repeated faults in the affected component.
  • Correlate device unavailability events with local network activity to identify potential trigger sources.
  • Monitor endpoint telemetry for abnormal restart patterns across fleets of Apple devices sharing common networks.

Monitoring Recommendations

  • Track OS version inventory to identify devices still running vulnerable builds prior to iOS/iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS/visionOS/watchOS 26.6.
  • Enable network segmentation logging to identify which devices coexist on untrusted broadcast domains.
  • Alert on repeated device reboots or availability drops within a short window across multiple Apple endpoints.

How to Mitigate CVE-2026-64724

Immediate Actions Required

  • Update all Apple devices to the fixed versions: iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
  • Inventory all Apple devices in the environment and prioritize patching for devices routinely connected to untrusted local networks.
  • Restrict affected devices from connecting to guest or public Wi-Fi networks until patches are applied.

Patch Information

Apple has released patches addressing CVE-2026-64724 across all affected platforms. Review the vendor advisories for platform-specific update instructions: Apple Security Support #128066, Apple Security Support #128067, Apple Security Support #128068, Apple Security Support #128069, Apple Security Support #128070, Apple Security Support #128071, and Apple Security Support #128072.

Workarounds

  • Segment Apple devices onto trusted VLANs and restrict local network peer-to-peer traffic where feasible.
  • Disable services that expose the vulnerable component on the local network until updates are applied.
  • Enforce use of managed networks with client isolation to reduce attacker adjacency on shared segments.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.