DIRAS TAKE
Urgent: this is a critical kernel memory flaw — apply the vendor updates for affected macOS releases immediately to remove the attack surface.
What is CVE-2026-64698?
Local applications can crash the kernel or disclose kernel memory on macOS, tracked as CVE-2026-64698. Apple resolved the vulnerability by changing kernel memory handling; affected releases are macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6. Exploitation requires running a malicious or specially crafted app on the target machine—no network access is needed but code execution on the host is required to trigger the flaw.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple macOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 14.x | before 14.8.8 | 14.8.8 |
| 15.x | before 15.7.8 | 15.7.8 |
| 26.x | before 26.6 | 26.6 |
Is CVE-2026-64698 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-64698
- Apply the macOS updates that contain the fixes: Sonoma 14.8.8, Sequoia 15.7.8, or Tahoe 26.6.
- Block or restrict execution of untrusted applications and enforce application allowlisting where possible.
- Monitor kernel crash logs and system telemetry for signs of abnormal terminations or memory access errors.
- Follow Apple’s update instructions and any additional vendor guidance for affected systems.
Frequently asked questions
Is CVE-2026-64698 being actively exploited?
There are no public reports of exploitation of CVE-2026-64698 as of 2026-09-29.
Which macOS versions are affected by CVE-2026-64698?
Affected releases are macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6.
Is there a patch for CVE-2026-64698?
Yes. Apple released fixes in Sonoma 14.8.8, Sequoia 15.7.8, and Tahoe 26.6.
Does CVE-2026-64698 require authentication?
No. The issue can be triggered by an app running on the system and does not require privileged credentials or network access.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64698
- cve.org/CVERecord?id=CVE-2026-64698
- support.apple.com/en-us/128067
- support.apple.com/en-us/128071
- support.apple.com/en-us/128072
- All Apple CVEs on CVE Radar
- CVEs published in September 2026