DIRAS TAKE
Urgent: install the vendor updates because Apple fixed this sandbox escape in 15.7.8 and 26.6; an app running locally can exploit the flaw to break out of its sandbox. Prioritise patching desktops that allow third-party app installation.
What is CVE-2026-64731?
A malicious app can break out of the macOS sandbox and gain broader access to the system, allowing local code to read or modify files beyond its sandbox. CVE-2026-64731 is a path-handling vulnerability (CWE-22) fixed in macOS Sequoia 15.7.8 and macOS Tahoe 26.6; versions before 15.7.8 on the 15.x branch and before 26.6 on the 26.x branch are affected. An attacker must be able to run a malicious application on the target system to exploit the issue. The weakness is classified as CWE-22 (Path Traversal).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple macOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 15.x | before 15.7.8 | 15.7.8 |
| 26.x | before 26.6 | 26.6 |
Is CVE-2026-64731 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-64731
- Apply the vendor updates: upgrade 15.x systems to 15.7.8 and 26.x systems to 26.6.
- Limit app installation to trusted sources and enforce app allowlisting where possible.
- Monitor endpoint logs for suspicious process activity and unexpected file access from sandboxed apps.
- Follow Apple's security guidance and audit macOS systems for untrusted or unsigned applications.
Frequently asked questions
Is CVE-2026-64731 being actively exploited?
There are no public reports of exploitation of CVE-2026-64731 as of 2026-09-29.
Which macOS versions are affected by CVE-2026-64731?
macOS on the 15.x branch before 15.7.8 and on the 26.x branch before 26.6 are affected.
Is there a patch for CVE-2026-64731?
Yes. Apple fixed the issue in macOS Sequoia 15.7.8 and macOS Tahoe 26.6; update affected systems to those releases.
Does CVE-2026-64731 require authentication?
The vulnerability requires a malicious application to run on the target macOS device; it is not a remote unauthenticated network flaw.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64731
- cve.org/CVERecord?id=CVE-2026-64731
- support.apple.com/en-us/128067
- support.apple.com/en-us/128071
- All Apple CVEs on CVE Radar
- CVEs published in September 2026