• PATCH AVAILABLE

CVE-2026-64767: pre-auth remote code execution in Apple macOS

A remote attacker can execute code or crash affected macOS systems without authentication. CVE-2026-64767 is a kernel buffer overflow that can allow an unauthenticated remote actor to cause system termination or corrupt kernel memory. Affected releases are macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6. The CVSS vector indicates network access is sufficient and no user interaction or privileges are required to exploit this flaw.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.0078
CWE
CWE-120
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent — this flaw allows remote, unauthenticated code execution or kernel corruption (no login needed), so prioritize patching systems exposed to untrusted networks and apply vendor updates immediately.

What is CVE-2026-64767?

A remote attacker can execute code or crash affected macOS systems without authentication. CVE-2026-64767 is a kernel buffer overflow that can allow an unauthenticated remote actor to cause system termination or corrupt kernel memory. Affected releases are macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6. The CVSS vector indicates network access is sufficient and no user interaction or privileges are required to exploit this flaw.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple macOS are affected?

BRANCHAFFECTEDFIXED
14.xbefore 14.8.814.8.8
15.xbefore 15.7.815.7.8
26.xbefore 26.626.6

Is CVE-2026-64767 being exploited?

There are no public reports of exploitation or public exploit code as of 2026-09-29.

How to fix CVE-2026-64767

  1. Install the vendor fixes: update to macOS Sonoma 14.8.8, Sequoia 15.7.8, or Tahoe 26.6 as appropriate.
  2. If you cannot update immediately, restrict network exposure of macOS hosts to trusted networks and block untrusted access.
  3. Monitor affected systems for crashes, kernel panics, and suspicious activity; collect logs for investigation.
  4. Follow Apple's security guidance and apply any additional mitigations the vendor publishes.

Frequently asked questions

Is CVE-2026-64767 being actively exploited?

There are no public reports of active exploitation or public exploit code as of 2026-09-29.

Which macOS versions are affected by CVE-2026-64767?

macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6 are listed as affected.

Is there a patch for CVE-2026-64767?

Yes. Apple released fixes in macOS Sonoma 14.8.8, Sequoia 15.7.8, and Tahoe 26.6.

Does CVE-2026-64767 require authentication?

No. The vulnerability can be exploited without authentication or user interaction against affected macOS releases.

References