• PATCH AVAILABLE

CVE-2026-64694: integer overflow in Apple macOS

A remote attacker can trigger an integer overflow in macOS and cause application or system instability, potentially leading to code execution. CVE-2026-64694 affects macOS Sequoia 15.x before 15.7.8, macOS Sonoma 14.x before 14.8.8, and macOS Tahoe 26.x before 26.6. The CVSS vector shows network attackability without authentication or user interaction, so attackers reachable over the network can attempt to exploit the flaw.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00585
CWE
CWE-190
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as urgent: the flaw is remotely reachable without authentication (CVSS AV:N/PR:N/UI:N) and vendor fixes are available for the affected branches; apply the updates immediately to exposed systems.

What is CVE-2026-64694?

A remote attacker can trigger an integer overflow in macOS and cause application or system instability, potentially leading to code execution. CVE-2026-64694 affects macOS Sequoia 15.x before 15.7.8, macOS Sonoma 14.x before 14.8.8, and macOS Tahoe 26.x before 26.6. The CVSS vector shows network attackability without authentication or user interaction, so attackers reachable over the network can attempt to exploit the flaw.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple macOS are affected?

BRANCHAFFECTEDFIXED
14.xbefore 14.8.814.8.8
15.xbefore 15.7.815.7.8
26.xbefore 26.626.6

Is CVE-2026-64694 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-64694

  1. Install the vendor fixes: upgrade to macOS Sonoma 14.8.8, Sequoia 15.7.8, or Tahoe 26.6 as applicable.
  2. If you cannot patch immediately, restrict network exposure of vulnerable hosts and block untrusted incoming connections.
  3. Monitor system and application logs for crashes or anomalous behavior that could indicate exploitation attempts.
  4. Follow Apple’s guidance and deploy updates via your usual update tools to ensure consistency across devices.

Frequently asked questions

Is CVE-2026-64694 being actively exploited?

There are no public reports of active exploitation of CVE-2026-64694 as of 2026-09-29.

Which macOS versions are affected by CVE-2026-64694?

Affected versions are macOS Sonoma 14.x before 14.8.8, Sequoia 15.x before 15.7.8, and Tahoe 26.x before 26.6.

Is there a patch for CVE-2026-64694?

Yes. Apple fixed the issue in macOS Sonoma 14.8.8, Sequoia 15.7.8, and Tahoe 26.6; apply those updates to remediate.

Does CVE-2026-64694 require authentication?

No. The reported CVSS vector indicates no authentication or user interaction is required, and the issue is reachable over the network.

References