CVE-2026-64732
published 2026-07-27CVE-2026-64732: This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6. An attacker with physical access may be able to…
PriorityP422medium4.6CVSS 3.1
AVPACLPRNUINSUCHINAN
EPSS
0.15%
4.7th percentile
This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6. An attacker with physical access may be able to access sensitive user data during iPhone Mirroring.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 26.6 | 26.6 |
| apple | ipados | < 26.6 | 26.6 |
| apple | iphone_os | < 26.6 | 26.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple iOS/iPadOS up to 26.5 State Management information disclosure
vuldb·2026-07-28
CVE-2026-64732 [LOW] Apple iOS/iPadOS up to 26.5 State Management information disclosure
A vulnerability classified as problematic was found in Apple iOS and iPadOS up to 26.5. This affects an unknown part of the component State Management. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2026-64732. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
This issue was addressed through improved state management.
ghsa_unreviewed·2026-07-27
CVE-2026-64732 [MEDIUM] CWE-284 This issue was addressed through improved state management.
This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6. An attacker with physical access may be able to access sensitive user data during iPhone Mirroring.
No detection rules found.
No public exploits indexed.
2026-07-27
Published