DIRAS TAKE
Urgent: apply vendor updates immediately — the flaw allows unauthenticated remote kernel memory corruption and Apple published fixes for 14.8.8, 15.7.8 and 26.6. If you cannot update, restrict network exposure to macOS hosts and increase monitoring.
What is CVE-2026-64697?
An unauthenticated remote attacker can cause kernel memory corruption and achieve remote code execution on macOS, potentially crashing the system or corrupting kernel memory. CVE-2026-64697 affects macOS Sonoma 14.x before 14.8.8, Sequoia 15.x before 15.7.8, and Tahoe 26.x before 26.6. According to the vendor fixes, exploitation requires only network access and does not require a logged-in user or additional privileges; the vulnerability was addressed by improved memory handling in the listed fixed releases.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple macOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 14.x | before 14.8.8 | 14.8.8 |
| 15.x | before 15.7.8 | 15.7.8 |
| 26.x | before 26.6 | 26.6 |
Is CVE-2026-64697 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-64697
- Install the vendor updates: macOS Sonoma 14.8.8, Sequoia 15.7.8, or Tahoe 26.6.
- Isolate or restrict network access to vulnerable macOS systems until patched.
- Monitor system logs and kernel crash reports for signs of memory corruption or unexpected reboots.
- Follow Apple guidance and apply any additional mitigations the vendor provides.
Frequently asked questions
Is CVE-2026-64697 being actively exploited?
There are no public reports of exploitation of CVE-2026-64697 as of 2026-09-29.
Which macOS versions are affected by CVE-2026-64697?
macOS Sonoma 14.x before 14.8.8, Sequoia 15.x before 15.7.8, and Tahoe 26.x before 26.6 are affected.
Is there a patch for CVE-2026-64697?
Yes; Apple released fixes in macOS Sonoma 14.8.8, Sequoia 15.7.8, and Tahoe 26.6.
What can an attacker do with CVE-2026-64697?
An attacker can cause kernel memory corruption that may lead to unexpected system termination or allow remote execution in the kernel on affected macOS systems.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64697
- cve.org/CVERecord?id=CVE-2026-64697
- support.apple.com/en-us/128067
- support.apple.com/en-us/128071
- support.apple.com/en-us/128072
- All Apple CVEs on CVE Radar
- CVEs published in September 2026