CVE-2026-64741
published 2026-07-27CVE-2026-64741: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app…
PriorityP423medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.19%
8.9th percentile
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read a persistent device identifier.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 26.6 | 26.6 |
| apple | ipados | < 26.6 | 26.6 |
| apple | iphone_os | < 26.6 | 26.6 |
| apple | tvos | < 26.6 | 26.6 |
| apple | visionos | < 26.6 | 26.6 |
| apple | watchos | < 26.6 | 26.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple iOS/iPadOS/tvOS/visionOS/watchOS up to 26.5 permission
vuldb·2026-07-28
CVE-2026-64741 [LOW] Apple iOS/iPadOS/tvOS/visionOS/watchOS up to 26.5 permission
A vulnerability identified as problematic has been detected in Apple iOS, iPadOS, tvOS, visionOS and watchOS up to 26.5. Affected by this vulnerability is an unknown functionality. The manipulation leads to permission issues.
This vulnerability is referenced as CVE-2026-64741. The attack can only be performed from a local environment. No exploit is available.
You should upgrade the affected component.
GHSA
A permissions issue was addressed with additional restrictions.
ghsa_unreviewed·2026-07-27
CVE-2026-64741 [MEDIUM] CWE-200 A permissions issue was addressed with additional restrictions.
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read a persistent device identifier.
No detection rules found.
No public exploits indexed.
2026-07-27
Published