Vulnary
← back to the feed
Critical· 9.3official fix available

CVE-2026-64740

A parsing issue in how directory paths are handled allows a malicious app to break out of its sandbox on affected Apple devices. The flaw is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, and tvOS 26.6. No known exploitation or public exploit has been reported.

publishedJul 27, 2026
last modifiedJul 28, 2026
sourcesNVD
severity · cvss
9.3
critical · how bad it is
exploitation · epss
<1%
6th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 27, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Users of iOS, iPadOS, macOS (Sequoia, Sonoma, Tahoe), and tvOS running versions prior to the patched releases.

02

Real-world impact

An attacker who can install a malicious app could escape the app sandbox and potentially access or modify data outside the app's permitted scope, leading to confidentiality, integrity, and availability impacts.

03

Why this severity

The CVSS v3.1 base score is 9.8 (Critical) due to network‑adjacent attack vector, low complexity, no privileges or user interaction required, and high impacts to confidentiality, integrity, and availability.

04

What to do about it

official fix available
recommended steps
  1. 01Update iOS and iPadOS to version 26.6 or later.
  2. 02Update macOS Sequoia to version 15.7.8 or later.
  3. 03Update macOS Sonoma to version 14.8.8 or later.
  4. 04Update macOS Tahoe to version 26.6 or later.
  5. 05Update tvOS to version 26.6 or later.

NVD-referenced vendor advisory

05

Timeline

  1. Jul 27, 2026 · 3d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 28, 2026 · 2d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorLocal
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →