DIRAS TAKE
Treat this as high priority: the bug requires no privileges to trigger and is fixed in macOS 26.6 and tvOS 26.6, so apply vendor updates promptly.
What is CVE-2026-64727?
An attacker-controlled app can cause unexpected system termination on macOS and tvOS, tracked as CVE-2026-64727. The flaw is a type confusion in memory handling and is fixed in macOS 26.6 and tvOS 26.6; versions before 26.6 are affected. Exploitation requires the ability to run a malicious or crafted app on the target system rather than network access or authentication.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple macOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| macOS 26.x | before 26.6 | 26.6 |
| tvOS 26.x | before 26.6 | 26.6 |
Is CVE-2026-64727 being exploited?
There are no public reports of exploitation of CVE-2026-64727 as of 2026-09-29.
How to fix CVE-2026-64727
- Update affected systems to macOS 26.6 and tvOS 26.6.
- Restrict or control app installation sources and enforce app notarization where possible.
- Monitor endpoint logs for crashes or unusual process terminations and investigate suspicious installed apps.
- Apply any additional vendor guidance or mitigations published by Apple.
Frequently asked questions
Is CVE-2026-64727 being actively exploited?
There are no public reports of active exploitation of CVE-2026-64727 as of 2026-09-29.
Which macOS versions are affected by CVE-2026-64727?
macOS 26.x versions before 26.6 are affected; the issue is also present in tvOS 26.x before 26.6.
Is there a patch for CVE-2026-64727?
Yes. Apple fixed the issue in macOS 26.6 and tvOS 26.6.
Does CVE-2026-64727 require authentication?
No. The vulnerability can be triggered by an app without prior privileges or authentication.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64727
- cve.org/CVERecord?id=CVE-2026-64727
- support.apple.com/en-us/128067
- support.apple.com/en-us/128069
- All Apple CVEs on CVE Radar
- CVEs published in September 2026