CVE-2026-64691
published 2026-07-27CVE-2026-64691: A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpected system…
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.15%
4.5th percentile
A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 26.6 | 26.6 |
| apple | macos | >= 26.0 < 26.6 | 26.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple macOS up to 26.5 buffer overflow
vuldb·2026-07-28
CVE-2026-64691 [CRITICAL] Apple macOS up to 26.5 buffer overflow
A vulnerability classified as critical was found in Apple macOS up to 26.5. The impacted element is an unknown function. Executing a manipulation can lead to buffer overflow.
This vulnerability appears as CVE-2026-64691. The attack requires local access. There is no available exploit.
Upgrading the affected component is advised.
GHSA
A buffer overflow was addressed with improved size validation.
ghsa_unreviewed·2026-07-27
CVE-2026-64691 [CRITICAL] CWE-120 A buffer overflow was addressed with improved size validation.
A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-27
Published