• PATCH AVAILABLE

CVE-2026-64731: sandbox escape in Apple macOS

A malicious app can break out of the macOS sandbox and gain broader access to the system, allowing local code to read or modify files beyond its sandbox. CVE-2026-64731 is a path-handling vulnerability (CWE-22) fixed in macOS Sequoia 15.7.8 and macOS Tahoe 26.6; versions before 15.7.8 on the 15.x branch and before 26.6 on the 26.x branch are affected. An attacker must be able to run a malicious application on the target system to exploit the issue.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00611
CWE
CWE-22
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: install the vendor updates because Apple fixed this sandbox escape in 15.7.8 and 26.6; an app running locally can exploit the flaw to break out of its sandbox. Prioritise patching desktops that allow third-party app installation.

What is CVE-2026-64731?

A malicious app can break out of the macOS sandbox and gain broader access to the system, allowing local code to read or modify files beyond its sandbox. CVE-2026-64731 is a path-handling vulnerability (CWE-22) fixed in macOS Sequoia 15.7.8 and macOS Tahoe 26.6; versions before 15.7.8 on the 15.x branch and before 26.6 on the 26.x branch are affected. An attacker must be able to run a malicious application on the target system to exploit the issue. The weakness is classified as CWE-22 (Path Traversal).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple macOS are affected?

BRANCHAFFECTEDFIXED
15.xbefore 15.7.815.7.8
26.xbefore 26.626.6

Is CVE-2026-64731 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-64731

  1. Apply the vendor updates: upgrade 15.x systems to 15.7.8 and 26.x systems to 26.6.
  2. Limit app installation to trusted sources and enforce app allowlisting where possible.
  3. Monitor endpoint logs for suspicious process activity and unexpected file access from sandboxed apps.
  4. Follow Apple's security guidance and audit macOS systems for untrusted or unsigned applications.

Frequently asked questions

Is CVE-2026-64731 being actively exploited?

There are no public reports of exploitation of CVE-2026-64731 as of 2026-09-29.

Which macOS versions are affected by CVE-2026-64731?

macOS on the 15.x branch before 15.7.8 and on the 26.x branch before 26.6 are affected.

Is there a patch for CVE-2026-64731?

Yes. Apple fixed the issue in macOS Sequoia 15.7.8 and macOS Tahoe 26.6; update affected systems to those releases.

Does CVE-2026-64731 require authentication?

The vulnerability requires a malicious application to run on the target macOS device; it is not a remote unauthenticated network flaw.

References