• PATCH AVAILABLE

CVE-2026-64704: pre-auth remote code execution in Apple macOS

An unauthenticated attacker can execute arbitrary code on macOS via a type confusion flaw (CVE-2026-64704). Affected releases include macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6; the vulnerability requires no user interaction or login. Apple fixed the issue by improving memory handling in the listed updates.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00585
CWE
CWE-843
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a remote, no-login-needed vulnerability with a critical CVSS rating; apply the vendor updates named below immediately to exposed systems.

What is CVE-2026-64704?

An unauthenticated attacker can execute arbitrary code on macOS via a type confusion flaw (CVE-2026-64704). Affected releases include macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6; the vulnerability requires no user interaction or login. Apple fixed the issue by improving memory handling in the listed updates.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple macOS are affected?

BRANCHAFFECTEDFIXED
14.xbefore 14.8.814.8.8
15.xbefore 15.7.815.7.8
26.xbefore 26.626.6

Is CVE-2026-64704 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-64704

  1. Install the updates that contain the fixes: 14.8.8 for 14.x, 15.7.8 for 15.x, and 26.6 for 26.x.
  2. If you cannot patch immediately, restrict network exposure of macOS hosts and disable unnecessary services reachable from untrusted networks.
  3. Monitor system and network logs for unusual activity and signs of compromise on macOS endpoints.
  4. Follow Apple's advisory and update processes for complete remediation and verification.

Frequently asked questions

Is CVE-2026-64704 being actively exploited?

There are no public reports of active exploitation as of 2026-09-29.

Which macOS versions are affected by CVE-2026-64704?

macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6 are listed as affected.

Is there a patch for CVE-2026-64704?

Yes; Apple provided fixes in macOS Sonoma 14.8.8, Sequoia 15.7.8, and Tahoe 26.6.

Does CVE-2026-64704 require authentication?

No; the vulnerability does not require authentication or user interaction.

References