• PATCH AVAILABLE

CVE-2026-64698: memory corruption in Apple macOS

Local applications can crash the kernel or disclose kernel memory on macOS, tracked as CVE-2026-64698. Apple resolved the vulnerability by changing kernel memory handling; affected releases are macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6. Exploitation requires running a malicious or specially crafted app on the target machine—no network access is needed but code execution on the host is required to trigger the flaw.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00585
CWE
CWE-119
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a critical kernel memory flaw — apply the vendor updates for affected macOS releases immediately to remove the attack surface.

What is CVE-2026-64698?

Local applications can crash the kernel or disclose kernel memory on macOS, tracked as CVE-2026-64698. Apple resolved the vulnerability by changing kernel memory handling; affected releases are macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6. Exploitation requires running a malicious or specially crafted app on the target machine—no network access is needed but code execution on the host is required to trigger the flaw.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple macOS are affected?

BRANCHAFFECTEDFIXED
14.xbefore 14.8.814.8.8
15.xbefore 15.7.815.7.8
26.xbefore 26.626.6

Is CVE-2026-64698 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-64698

  1. Apply the macOS updates that contain the fixes: Sonoma 14.8.8, Sequoia 15.7.8, or Tahoe 26.6.
  2. Block or restrict execution of untrusted applications and enforce application allowlisting where possible.
  3. Monitor kernel crash logs and system telemetry for signs of abnormal terminations or memory access errors.
  4. Follow Apple’s update instructions and any additional vendor guidance for affected systems.

Frequently asked questions

Is CVE-2026-64698 being actively exploited?

There are no public reports of exploitation of CVE-2026-64698 as of 2026-09-29.

Which macOS versions are affected by CVE-2026-64698?

Affected releases are macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6.

Is there a patch for CVE-2026-64698?

Yes. Apple released fixes in Sonoma 14.8.8, Sequoia 15.7.8, and Tahoe 26.6.

Does CVE-2026-64698 require authentication?

No. The issue can be triggered by an app running on the system and does not require privileged credentials or network access.

References