DIRAS TAKE
Urgently install the vendor fixes: this is a critical (CVSS 9.8) sandbox-escape bug that lets an app escalate beyond its sandbox; apply the listed macOS updates immediately.
What is CVE-2026-64702?
A malicious or vulnerable app can break out of the macOS application sandbox, allowing local code to gain broader privileges on the system; see CVE-2026-64702. The issue affects macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6. Exploitation requires an app running on the affected macOS host.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple macOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 14.x | before 14.8.8 | 14.8.8 |
| 15.x | before 15.7.8 | 15.7.8 |
| 26.x | before 26.6 | 26.6 |
Is CVE-2026-64702 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-64702
- Install the vendor updates that fix the issue: 14.8.8, 15.7.8, or 26.6 as appropriate for your macOS release.
- Block untrusted or unnecessary apps from running and restrict software installation to managed channels.
- Monitor endpoints for unusual privilege escalation and audit application behavior for sandbox violations.
- Apply the vendor's additional guidance and configuration recommendations for app sandboxing and containment.
Frequently asked questions
Is CVE-2026-64702 being actively exploited?
There are no public reports of exploitation of CVE-2026-64702 as of 2026-09-29.
Which macOS versions are affected by CVE-2026-64702?
macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6 are affected.
Is there a patch for CVE-2026-64702?
Yes. Apple fixed the issue in macOS Sonoma 14.8.8, Sequoia 15.7.8, and Tahoe 26.6—install the appropriate update.
Does CVE-2026-64702 require authentication?
Exploitation involves an app escaping its sandbox, so it requires an app to run on the macOS host rather than remote authentication.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64702
- cve.org/CVERecord?id=CVE-2026-64702
- support.apple.com/en-us/128067
- support.apple.com/en-us/128071
- support.apple.com/en-us/128072
- All Apple CVEs on CVE Radar
- CVEs published in September 2026