CVE-2026-64788Disclosure(apple / ipados)

LOWCVSS 5.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-09-23)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
ipadosiphone_osmacos

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-19: 1Mentions · 2026-09-21: 1Mentions · 2026-09-23: 2Technical Details · 2026-08-19: 1Technical Details · 2026-09-21: 1Technical Details · 2026-09-23: 208-1909-2109-23
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Classification over time
DateTotalLabels
2026-08-191
General1
2026-09-211
Disclosure1
2026-09-232
Disclosure2
Full discourse4 posts
  • habib@hbeeb2001
    Disclosure

    1. نطاق ثغرات النواة البرمجية (Kernel & Security Bugs) النطاق المدعوم: من iOS 26.0 إلى iOS 26.6. الثغرات الشاملة في هذا النطاق: ⁠CVE-2026-64788⁠ (IOGPUFamily UAF): تمنح صلاحيات قراءة وكتابة عالية داخل ذاكرة النواة. ⁠ يتبع ..

    Post summary

    The text discloses a kernel use-after-free vulnerability (CVE-2026-64788) in iOS 26.0-26.6, describing its impact as high-level kernel memory read/write access, but does not mention a PoC, exploit, active exploitation, or specific patch.

    20010255
    198 followersView on X
  • habib@hbeeb2001
    Disclosure

    - ثغرة التحكم والقراءة/الكتابة في النواة (⁠CVE-2026-64788⁠): المفهوم: خلل برمجيات الرسوميات IOGPU من نوع (Use-After-Free) يمنح الباحث صلاحية التحكم المباشر بالقراءة والكتابة داخل ذاكرة النواة (Kernel Heap).

    Post summary

    The text discloses a new kernel vulnerability (CVE-2026-64788) in the IOGPU graphics driver, describing a use‑after‑free flaw that grants kernel read/write control.

    1000070
    197 followersView on X
  • Tech Start XYZ@TechStartXYZ
    General

    O pacote também eliminou: • Bypass de IPSec: Interceptação de tráfego de rede sem autenticação válida. • Falhas no Kernel: 3 vulnerabilidades de leitura indevida da memória mais protegida do sistema. • Corrupção no IOGPUFamily (CVE-2026-64788): Acionada via conteúdo web no Safari.

    Post summary

    The statement enumerates several technical weaknesses, including a CVE affecting IOGPUFamily triggered by Safari content, but offers no evidence of exploitation, PoC, or remediation.

    1000033
    168 followersView on X
  • habib@hbeeb2001
    Disclosure

    *-بالنسبة للأجهزة الأحدث من معالج A14 فما فوق (مثل iPhone 12, 13, 14, 15, 16) تستفيد من ثغرات النواة الثلاث(⁠CVE-2026-84530⁠, ⁠CVE-2026-65343⁠, ⁠CVE-2026-64788⁠) وتفتقد لثغرة الإقلاع العتادية ⁠usbliter8⁠؛ النسبة المكتملة الأجهزة هو 55%، والنسبة المتبقية لها هي 45%

    Post summary

    The text announces kernel vulnerability details (three CVEs) affecting A14+ iPhones, noting the absence of the usbliter8 hardware boot flaw and citing completion percentages, but provides no PoC link, exploit tool, patch, or active-exploitation evidence.

    0000090
    197 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---

Explore more