CVE-2026-64691: Apple macOS

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

Affected products

  • Apple macOS: from 26.0, before 26.6 (fixed in 26.6)

Published 2026-07-27. Last modified 2026-07-28.