CVE-2026-64744
published 2026-07-27CVE-2026-64744: An information leakage was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may…
PriorityP425medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.13%
3.1th percentile
An information leakage was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 14.8.8 | 14.8.8 |
| apple | macos | < 15.7.8 | 15.7.8 |
| apple | macos | < 26.6 | 26.6 |
| apple | macos | >= 14.0 < 14.8.8 | 14.8.8 |
| apple | macos | >= 15.0 < 15.7.8 | 15.7.8 |
| apple | macos | >= 26.0 < 26.6 | 26.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple macOS up to 14.8.7/15.7.7/26.5 Kernel information disclosure
vuldb·2026-07-28
CVE-2026-64744 [LOW] Apple macOS up to 14.8.7/15.7.7/26.5 Kernel information disclosure
A vulnerability was found in Apple macOS up to 14.8.7/15.7.7/26.5 and classified as problematic. The affected element is an unknown function of the component Kernel. The manipulation results in information disclosure.
This vulnerability is known as CVE-2026-64744. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
An information leakage was addressed with additional validation.
ghsa_unreviewed·2026-07-27
CVE-2026-64744 [MEDIUM] CWE-200 An information leakage was addressed with additional validation.
An information leakage was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.
No detection rules found.
No public exploits indexed.
2026-07-27
Published