CVE-2026-64740
A parsing issue in how directory paths are handled allows a malicious app to break out of its sandbox on affected Apple devices. The flaw is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, and tvOS 26.6. No known exploitation or public exploit has been reported.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of iOS, iPadOS, macOS (Sequoia, Sonoma, Tahoe), and tvOS running versions prior to the patched releases.
Real-world impact
An attacker who can install a malicious app could escape the app sandbox and potentially access or modify data outside the app's permitted scope, leading to confidentiality, integrity, and availability impacts.
Why this severity
The CVSS v3.1 base score is 9.8 (Critical) due to network‑adjacent attack vector, low complexity, no privileges or user interaction required, and high impacts to confidentiality, integrity, and availability.
What to do about it
- 01Update iOS and iPadOS to version 26.6 or later.
- 02Update macOS Sequoia to version 15.7.8 or later.
- 03Update macOS Sonoma to version 14.8.8 or later.
- 04Update macOS Tahoe to version 26.6 or later.
- 05Update tvOS to version 26.6 or later.
NVD-referenced vendor advisory
Timeline
- Jul 27, 2026 · 3d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 28, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- support.apple.com/en-us/128066release notesvendor advisory
- support.apple.com/en-us/128067release notesvendor advisory
- support.apple.com/en-us/128069release notesvendor advisory
- support.apple.com/en-us/128071release notesvendor advisory
- support.apple.com/en-us/128072release notesvendor advisory