• PATCH AVAILABLE

CVE-2026-64727: local type confusion in Apple macOS

An attacker-controlled app can cause unexpected system termination on macOS and tvOS, tracked as CVE-2026-64727. The flaw is a type confusion in memory handling and is fixed in macOS 26.6 and tvOS 26.6; versions before 26.6 are affected. Exploitation requires the ability to run a malicious or crafted app on the target system rather than network access or authentication.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00499
CWE
CWE-843
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as high priority: the bug requires no privileges to trigger and is fixed in macOS 26.6 and tvOS 26.6, so apply vendor updates promptly.

What is CVE-2026-64727?

An attacker-controlled app can cause unexpected system termination on macOS and tvOS, tracked as CVE-2026-64727. The flaw is a type confusion in memory handling and is fixed in macOS 26.6 and tvOS 26.6; versions before 26.6 are affected. Exploitation requires the ability to run a malicious or crafted app on the target system rather than network access or authentication.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple macOS are affected?

BRANCHAFFECTEDFIXED
macOS 26.xbefore 26.626.6
tvOS 26.xbefore 26.626.6

Is CVE-2026-64727 being exploited?

There are no public reports of exploitation of CVE-2026-64727 as of 2026-09-29.

How to fix CVE-2026-64727

  1. Update affected systems to macOS 26.6 and tvOS 26.6.
  2. Restrict or control app installation sources and enforce app notarization where possible.
  3. Monitor endpoint logs for crashes or unusual process terminations and investigate suspicious installed apps.
  4. Apply any additional vendor guidance or mitigations published by Apple.

Frequently asked questions

Is CVE-2026-64727 being actively exploited?

There are no public reports of active exploitation of CVE-2026-64727 as of 2026-09-29.

Which macOS versions are affected by CVE-2026-64727?

macOS 26.x versions before 26.6 are affected; the issue is also present in tvOS 26.x before 26.6.

Is there a patch for CVE-2026-64727?

Yes. Apple fixed the issue in macOS 26.6 and tvOS 26.6.

Does CVE-2026-64727 require authentication?

No. The vulnerability can be triggered by an app without prior privileges or authentication.

References