CVE-2026-64731: Apple macOS

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.

Affected products

  • Apple macOS: from 15.0, before 15.7.8 (fixed in 15.7.8); from 26.0, before 26.6 (fixed in 26.6)

Published 2026-07-27. Last modified 2026-07-28.