Multiple vulnerabilities in Apple products (August 18, 2026)
Multiple vulnerabilities were discovered in Apple products. Some of them allow an attacker to cause arbitrary code execution, privilege escalation and remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities in Apple products enable arbitrary code execution, privilege escalation, and remote denial-of-service attacks.
- Who is affected
- Users of various Apple products and services affected by the listed CVEs.
- Urgency
- Unknown severity specified but RCE, privilege escalation, and DoS capabilities indicate high risk requiring prompt patching.
- Action
- Check Apple security updates for CVE-2026-64734, CVE-2026-64788, CVE-2026-65337, CVE-2026-65331, CVE-2026-43738, CVE-2026-43811, CVE-2026-43799, and CVE-2026-64770; apply all available patches.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1038/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-647340.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647880.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-653370.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-653310.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-437380.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-438110.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-437990.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647700.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647490.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647390.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] cURL: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Apple macOS, iOS and iPadOS: Multiple vulnerabilitiescert-bund
- unknownApple Products Multiple Vulnerabilitieshkcert
- mediumCVE-2026-65351: This issue was addressed through improved state management. This issue is fixed in Safari 26.6…nvd
- highCVE-2026-65343: A use after free issue was addressed with improved memory management. This issue is fixed in i…nvd
- mediumCVE-2026-65341: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, i…nvd
- mediumCVE-2026-65340: This issue was addressed through improved state management. This issue is fixed in Safari 26.6…nvd
- mediumCVE-2026-65339: A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS…nvd
- mediumCVE-2026-65337: This issue was addressed through improved state management. This issue is fixed in Safari 26.6…nvd
- mediumCVE-2026-65332: This issue was addressed through improved state management. This issue is fixed in Safari 26.6…nvd
- mediumCVE-2026-65331: This issue was addressed through improved state management. This issue is fixed in Safari 26.6…nvd
- mediumCVE-2026-64788: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and i…nvd
Recent advisories for Apple products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownApple Products Multiple Vulnerabilitieshkcert · 2026-08-18
- unknownApple Products Multiple Vulnerabilitieshkcert · 2026-07-28
- unknownMultiple vulnerabilities in Apple products (July 28, 2026)cert-fr-avis · 2026-07-28
- unknownApple Products Multiple Vulnerabilitieshkcert · 2026-07-06
- unknownMultiple vulnerabilities in Apple products (June 30, 2026)cert-fr-avis · 2026-06-30
- criticalexploitedCVE-2025-43510: Apple Multiple Products Improper Locking Vulnerabilitycisa-kev · 2026-03-20
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Oracle Virtualization (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Oracle Weblogic (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Axis products (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Google Chrome (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Oracle MySQL (August 19, 2026)2026-08-19