DIRAS TAKE
Urgent: this is a remote, no-login-needed vulnerability with a critical CVSS rating; apply the vendor updates named below immediately to exposed systems.
What is CVE-2026-64704?
An unauthenticated attacker can execute arbitrary code on macOS via a type confusion flaw (CVE-2026-64704). Affected releases include macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6; the vulnerability requires no user interaction or login. Apple fixed the issue by improving memory handling in the listed updates.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple macOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 14.x | before 14.8.8 | 14.8.8 |
| 15.x | before 15.7.8 | 15.7.8 |
| 26.x | before 26.6 | 26.6 |
Is CVE-2026-64704 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-64704
- Install the updates that contain the fixes: 14.8.8 for 14.x, 15.7.8 for 15.x, and 26.6 for 26.x.
- If you cannot patch immediately, restrict network exposure of macOS hosts and disable unnecessary services reachable from untrusted networks.
- Monitor system and network logs for unusual activity and signs of compromise on macOS endpoints.
- Follow Apple's advisory and update processes for complete remediation and verification.
Frequently asked questions
Is CVE-2026-64704 being actively exploited?
There are no public reports of active exploitation as of 2026-09-29.
Which macOS versions are affected by CVE-2026-64704?
macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6 are listed as affected.
Is there a patch for CVE-2026-64704?
Yes; Apple provided fixes in macOS Sonoma 14.8.8, Sequoia 15.7.8, and Tahoe 26.6.
Does CVE-2026-64704 require authentication?
No; the vulnerability does not require authentication or user interaction.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64704
- cve.org/CVERecord?id=CVE-2026-64704
- support.apple.com/en-us/128067
- support.apple.com/en-us/128071
- support.apple.com/en-us/128072
- All Apple CVEs on CVE Radar
- CVEs published in September 2026