CVE-2026-64715: Use After Free
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected process crash.
Other sources
Accessibility. This issue was addressed through improved state management.
— Apple
AirDrop. A reachable assertion was addressed with improved input validation.
— Apple
APFS. The issue was addressed with improved memory handling.
— Apple
App Store. This issue was addressed with improved checks.
— Apple
AppleDouble. A buffer overflow was addressed with improved bounds checking.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.6.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.6.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.7.10
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-65339
- CVE-2026-65347
- CVE-2026-65346
- CVE-2026-64788
- CVE-2026-65343
- CVE-2026-65349
- CVE-2026-65330
- CVE-2026-65329
- CVE-2026-64784
- CVE-2026-43795
- CVE-2026-65338
- CVE-2026-65341
- CVE-2026-64782
- CVE-2026-64781
- CVE-2026-65351
- CVE-2026-65340
- CVE-2026-65337
- CVE-2026-65336
- CVE-2026-65335
- CVE-2026-65333
- CVE-2026-65332
- CVE-2026-65331
- CVE-2026-64715
- CVE-2026-64780
- CVE-2026-65334
- CVE-2026-43794
- CVE-2026-64787
- CVE-2026-64778
- CVE-2026-64779
- CVE-2026-64732
- CVE-2026-43667
- CVE-2026-64695
- CVE-2026-43801
- CVE-2026-43776
- CVE-2026-64725
- CVE-2026-64747
- CVE-2026-64762
- CVE-2026-64707
- CVE-2026-43811
- CVE-2026-64746
- CVE-2026-64734
- CVE-2026-43797
- CVE-2026-43673
- CVE-2026-43744
- CVE-2026-43803
- CVE-2026-43711
- CVE-2026-43738
- CVE-2026-43802
- CVE-2026-3784
- CVE-2026-3783
- CVE-2026-43714
- CVE-2026-64742
- CVE-2026-64740
- CVE-2026-43796
- CVE-2026-64692
- CVE-2026-64716
- CVE-2026-28990
- CVE-2026-43661
- CVE-2026-43818
- CVE-2026-64693
- CVE-2026-39877
- CVE-2026-64760
- CVE-2026-64749
- CVE-2026-64744
- CVE-2026-43778
- CVE-2026-64735
- CVE-2026-43822
- CVE-2026-43799
- CVE-2026-64700
- CVE-2026-43724
- CVE-2026-43769
- CVE-2026-43722
- CVE-2026-64721
- CVE-2026-43809
- CVE-2026-43757
- CVE-2026-43754
- CVE-2026-64723
- CVE-2026-39868
- CVE-2026-43810
- CVE-2026-64709
- CVE-2026-4424
- CVE-2026-28973
- CVE-2026-64739
- CVE-2026-64743
- CVE-2026-64738
- CVE-2026-64724
- CVE-2026-43723
- CVE-2026-43807
- CVE-2026-43733
- CVE-2026-43729
- CVE-2026-64772
- CVE-2026-64774
- CVE-2026-64770
- CVE-2026-64769
- CVE-2026-64722
- CVE-2026-64768
- CVE-2026-64771
- CVE-2026-43812
- CVE-2026-64764
- CVE-2026-64763
- CVE-2026-64766
- CVE-2026-64765
- CVE-2026-43800
- CVE-2026-28996
- CVE-2026-43658
- CVE-2026-28984
- CVE-2026-28958
- CVE-2026-28947
- CVE-2026-43727
- CVE-2026-43735
- CVE-2026-39872
- CVE-2026-43663
- CVE-2026-64757
- CVE-2026-43676
- CVE-2026-43734
- CVE-2026-43726
- CVE-2026-43699
- CVE-2026-43742
- CVE-2026-43725
- CVE-2026-43731
- CVE-2026-43705
- CVE-2026-43708
- CVE-2026-43700
- CVE-2026-43701
- CVE-2026-43745
- CVE-2026-43720
- CVE-2026-43821
- CVE-2026-43717
- CVE-2026-28979
- CVE-2026-64719
- CVE-2026-64726
- CVE-2026-64755
Frequently Asked Questions
What is the severity of CVE-2026-64715?
CVE-2026-64715 is considered a moderate severity vulnerability affecting Apple iOS, iPadOS, and macOS.
How do I fix CVE-2026-64715?
To fix CVE-2026-64715, users should update their devices to the latest version of Apple iOS, iPadOS, or macOS that addresses this issue.
What devices are affected by CVE-2026-64715?
CVE-2026-64715 affects Apple devices running iOS, iPadOS, and macOS Tahoe.
What type of vulnerability is CVE-2026-64715?
CVE-2026-64715 involves issues with input validation and memory handling, making it an accessibility and buffer overflow vulnerability.
When was CVE-2026-64715 published?
CVE-2026-64715 was published on August 17, 2026.