DIRAS TAKE
Apply Apple’s published updates for Sonoma 14.8.8, Sequoia 15.7.8 and Tahoe 26.6 promptly — patched builds are available and remove the vulnerability.
What is CVE-2026-64703?
An app can trigger a use-after-free vulnerability in macOS that may cause a denial-of-service; tracked as CVE-2026-64703. The flaw affects macOS Sonoma 14.x before 14.8.8, Sequoia 15.x before 15.7.8, and Tahoe 26.x before 26.6. Exploitation requires running or convincing a user to run a malicious or specially crafted app on the targeted macOS system; no network access or elevated privileges are documented as prerequisites in the available information. Apple fixed the issue by improving memory management in the listed updates. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple macOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 14.x | before 14.8.8 | 14.8.8 |
| 15.x | before 15.7.8 | 15.7.8 |
| 26.x | before 26.6 | 26.6 |
Is CVE-2026-64703 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-64703
- Install the Apple updates: upgrade affected systems to macOS 14.8.8, 15.7.8, or 26.6 as appropriate.
- Prevent installation of untrusted applications and enforce application whitelisting where possible.
- Monitor crash, kernel panic and system logs for unexplained application or system crashes.
- Follow Apple’s security guidance and verify all endpoints are patched in your inventory.
Frequently asked questions
Is CVE-2026-64703 being actively exploited?
There are no public reports of exploitation of CVE-2026-64703 as of 2026-09-29.
Which macOS versions are affected by CVE-2026-64703?
macOS Sonoma 14.x before 14.8.8, Sequoia 15.x before 15.7.8, and Tahoe 26.x before 26.6 are listed as affected.
Is there a patch for CVE-2026-64703?
Yes. Apple addressed the issue in macOS updates Sonoma 14.8.8, Sequoia 15.7.8, and Tahoe 26.6.
Does CVE-2026-64703 require authentication?
Exploitation requires running or delivering a malicious app on the target macOS device rather than additional authentication.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64703
- cve.org/CVERecord?id=CVE-2026-64703
- support.apple.com/en-us/128067
- support.apple.com/en-us/128071
- support.apple.com/en-us/128072
- All Apple CVEs on CVE Radar
- CVEs published in September 2026