CVE-2026-64731
published 2026-07-27CVE-2026-64731: A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to…
PriorityP341critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.16%
5.5th percentile
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 15.7.8 | 15.7.8 |
| apple | macos | < 26.6 | 26.6 |
| apple | macos | >= 15.0 < 15.7.8 | 15.7.8 |
| apple | macos | >= 26.0 < 26.6 | 26.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple macOS up to 15.7.7/26.5 privileges management
vuldb·2026-07-28
CVE-2026-64731 [CRITICAL] Apple macOS up to 15.7.7/26.5 privileges management
A vulnerability, which was classified as critical, was found in Apple macOS up to 15.7.7/26.5. This issue affects some unknown processing. Executing a manipulation can lead to improper privilege management.
This vulnerability appears as CVE-2026-64731. The attack requires local access. There is no available exploit.
You should upgrade the affected component.
GHSA
A path handling issue was addressed with improved validation.
ghsa_unreviewed·2026-07-27
CVE-2026-64731 [CRITICAL] CWE-22 A path handling issue was addressed with improved validation.
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-27
Published