Apple macOS Macintosh Operating System
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Apple macOS.
Recent Apple macOS Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 128072 | macOS Sonoma 14.8.8 - Apple Security Content | July 27, 2026 |
| 128071 | macOS Sequoia 15.7.8 - Apple Security Content | July 27, 2026 |
| 128067 | macOS Tahoe 26.6 - Apple Security Content | July 27, 2026 |
| 127595 | macOS Tahoe 26.5.2 - Apple Security Content | June 29, 2026 |
| 127115 | macOS Tahoe 26.5 - Apple Security Content | May 11, 2026 |
| 127117 | macOS Sonoma 14.8.7 - Apple Security Content | May 11, 2026 |
| 127116 | macOS Sequoia 15.7.7 - Apple Security Content | May 11, 2026 |
| 126795 | macOS Sequoia 15.7.5 - Apple Security Content | March 24, 2026 |
| 126796 | macOS Sonoma 14.8.5 - Apple Security Content | March 24, 2026 |
| 126794 | macOS Tahoe 26.4 - Apple Security Content | March 24, 2026 |
Known Exploited Apple macOS Vulnerabilities
The following Apple macOS vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Apple macOS Use-After-Free Vulnerability |
Apple macOS contains a use-after-free vulnerability that could allow for privilege escalation. CVE-2019-8526 Exploit Probability: 0.7% |
April 17, 2023 |
| Apple macOS Out-of-Bounds Write Vulnerability |
macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges. CVE-2022-22675 Exploit Probability: 12.6% |
April 4, 2022 |
| Apple macOS Out-of-Bounds Read Vulnerability |
macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory. CVE-2022-22674 Exploit Probability: 1.1% |
April 4, 2022 |
| Apple macOS Input Validation Error |
A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited. CVE-2021-30713 Exploit Probability: 6.6% |
November 3, 2021 |
| Apple macOS Policy Subsystem Gatekeeper Bypass |
A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited. CVE-2021-30657 Exploit Probability: 68.5% |
November 3, 2021 |
The vulnerability CVE-2021-30657: Apple macOS Policy Subsystem Gatekeeper Bypass is in the top 1% of the currently known exploitable vulnerabilities. The vulnerability CVE-2022-22675: Apple macOS Out-of-Bounds Write Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.
Apple macOS EOL Dates
Ensure that you are using a supported version of Apple macOS. Here are some end of life, and end of support dates for Apple macOS.
| Release | EOL Date | Status |
|---|---|---|
| 26 | - |
Active
|
| 15 | - |
Active
|
| 14 | - |
Active
|
| 13 | September 15, 2025 |
EOL
Apple macOS 13 became EOL in 2025. |
| 12 | September 16, 2024 |
EOL
Apple macOS 12 became EOL in 2024. |
| 11 | February 2, 2026 |
EOL
Apple macOS 11 became EOL in 2026. |
| 10.15 | February 2, 2026 |
EOL
Apple macOS 10.15 became EOL in 2026. |
| 10.14 | October 25, 2021 |
EOL
Apple macOS 10.14 became EOL in 2021. |
| 10.13 | December 1, 2020 |
EOL
Apple macOS 10.13 became EOL in 2020. |
| 10.12 | October 1, 2019 |
EOL
Apple macOS 10.12 became EOL in 2019. |
| 10.11 | December 1, 2018 |
EOL
Apple macOS 10.11 became EOL in 2018. |
| 10.9 | December 1, 2016 |
EOL
Apple macOS 10.9 became EOL in 2016. |
| 10.8 | August 13, 2015 |
EOL
Apple macOS 10.8 became EOL in 2015. |
| 10.7 | October 4, 2012 |
EOL
Apple macOS 10.7 became EOL in 2012. |
| 10.6 | July 25, 2011 |
EOL
Apple macOS 10.6 became EOL in 2011. |
| 10.5 | August 13, 2009 |
EOL
Apple macOS 10.5 became EOL in 2009. |
| 10.4 | November 14, 2007 |
EOL
Apple macOS 10.4 became EOL in 2007. |
| 10.3 | April 15, 2005 |
EOL
Apple macOS 10.3 became EOL in 2005. |
| 10.2 | October 3, 2003 |
EOL
Apple macOS 10.2 became EOL in 2003. |
| 10.1 | June 6, 2002 |
EOL
Apple macOS 10.1 became EOL in 2002. |
By the Year
In 2026 there have been 473 vulnerabilities in Apple macOS with an average score of 6.9 out of ten. Last year, in 2025 macOS had 679 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in macOS in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.29.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 473 | 6.91 |
| 2025 | 679 | 6.62 |
| 2024 | 543 | 6.42 |
| 2023 | 426 | 6.73 |
| 2022 | 381 | 7.10 |
| 2021 | 500 | 7.01 |
| 2020 | 342 | 7.24 |
| 2019 | 305 | 7.62 |
| 2018 | 89 | 7.25 |
It may take a day or so for new macOS vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Apple macOS Security Vulnerabilities
Out-of-Bounds Read in macOS (Sequoia/Sonoma/Tahoe) Up To 15.7.8/14.8.8/26.6
CVE-2026-43757
9.8 - Critical
- July 27, 2026
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
Out-of-bounds Read
macOS Authorization & Sandbox Break Fix (Sequoia, Sonoma)
CVE-2026-64737
8.2 - High
- July 27, 2026
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.
Authorization
macOS App Data Access Vulnerability (Fixed in Sequoia 15.7.8)
CVE-2026-43782
5.5 - Medium
- July 27, 2026
This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.
Information Disclosure
Apple OS Race Condition Enables Kernel Write fixed in iOS 26.6, macOS 15.7.8
CVE-2026-43805
9.8 - Critical
- July 27, 2026
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
Race Condition
Memory Handling Leak in macOS SMB Client Causes System Termination (Pre15.7/14.8/26.6)
CVE-2026-39873
9.8 - Critical
- July 27, 2026
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a malicious SMB server may lead to unexpected system termination.
Buffer Overflow
macOS kernel memory disclosure via bounds check flaw (before Sequoia 15.7.8)
CVE-2026-64776
5.5 - Medium
- July 27, 2026
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.
Out-of-bounds Read
iOS/macOS Code Signing Bypass (CVE-2026-43813) Fixed in 26.6
CVE-2026-43813
7.1 - High
- July 27, 2026
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A maliciously crafted app may be able to bypass code signing enforcement.
Improper Input Validation
Apple OS State Management Data Leak (CVE-2026-64721) - fixed in 26.6
CVE-2026-64721
5.5 - Medium
- July 27, 2026
This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
Improper Control of a Resource Through its Lifetime
macOS Info Disclosure Vulnerability Fixed in Sequoia 15.7.8 & Sonoma 14.8.8
CVE-2026-20672
5.5 - Medium
- July 27, 2026
An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to access sensitive user data.
Information Disclosure
Apple OS Sandbox Escape via Path Validation (iOS 26.6, macOS Sequoia 15.7.8)
CVE-2026-64740
9.3 - Critical
- July 27, 2026
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. A malicious app may be able to break out of its sandbox.
Directory traversal
Buffer overflow in macOS Tahoe before 26.6
CVE-2026-64691
9.8 - Critical
- July 27, 2026
A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
Classic Buffer Overflow
Apple OS Audio Framework Memory Corruption via Malicious Audio File (iOS 26.6+)
CVE-2026-43673
7.8 - High
- July 27, 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted audio file may corrupt process memory.
Buffer Overflow
SAFARI USE-AFTER-FREE CRASH VULN FIXED IN 26.6
CVE-2026-64783
8.8 - High
- July 27, 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Dangling pointer
macOS Sequoia 15.7.8 OOB Read CVE-2026-43809
CVE-2026-43809
9.8 - Critical
- July 27, 2026
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
Out-of-bounds Read
Apple macOS ScreenSharing VNC Password Disclosure Before 15.7.8/14.8.8
CVE-2026-43665
5.5 - Medium
- July 27, 2026
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able to determine the legacy VNC password configured for Screen Sharing.
AuthZ
Remote DoS via Improper Input Validation in macOS 15.7.8/14.8.8/26.6
CVE-2026-43777
7.5 - High
- July 27, 2026
This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote attacker may be able to cause a denial of service.
Improper Input Validation
Apple OS Use-After-Free before 26.6 (iOS & macOS)
CVE-2026-43799
9.8 - Critical
- July 27, 2026
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
Dangling pointer
Apple OS Buffer Overflow Fixed in iOS 26.6 / macOS 15.7.8
CVE-2026-43776
7.8 - High
- July 27, 2026
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
Classic Buffer Overflow
macOS Gatekeeper ZIP Quarantine Bypass (fixed 15.7.8/14.8.8)
CVE-2026-28900
5.5 - Medium
- July 27, 2026
A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks.
Authentication Bypass by Spoofing
Auth bypass via state mgmt in macOS 15.7.8, 14.8.8, 26.6
CVE-2026-43672
7.1 - High
- July 27, 2026
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious application may be able to bypass Privacy preferences.
AuthZ
macOS App Access Issue with Sensitive Data fixed in 14.8.8/26.6
CVE-2026-43760
5.5 - Medium
- July 27, 2026
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data.
Authorization
Apple OS ImageProcessor Memory Corruption (CVE-2026-64716) before 26.6
CVE-2026-64716
7.8 - High
- July 27, 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted image may corrupt process memory.
Buffer Overflow
macOS Kernel Race Condition Causing Termination (Fixed 15.7.8/14.8.8/26.6)
CVE-2026-28982
9.8 - Critical
- July 27, 2026
A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
Race Condition
Safari Memory Corruption Fixed in 26.6 (iOS, macOS, watchOS, visionOS)
CVE-2026-64757
8.8 - High
- July 27, 2026
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Buffer Overflow
Apple OSes UAF Fix in 26.6
CVE-2026-64700
9.8 - Critical
- July 27, 2026
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
Dangling pointer
Race Condition in Apple OS 26.6 Can Cause System Crash
CVE-2026-64720
9.8 - Critical
- July 27, 2026
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
Race Condition
macOS Gatekeeper ZIP Bypass (before 15.7.8 & 14.8.8)
CVE-2026-28849
5.5 - Medium
- July 27, 2026
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks.
Authentication Bypass by Spoofing
Apple OS Use-After-Free (iOS 26.6, macOS 15.7.8)
CVE-2026-43812
9.8 - Critical
- July 27, 2026
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. An app may be able to cause unexpected system termination.
Dangling pointer
Safari DoS via State Mgmt in 26.5+
CVE-2026-43804
6.5 - Medium
- July 27, 2026
This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. Visiting a website may lead to an app denial-of-service.
Resource Exhaustion
macOS logic flaw enabling app data access (fixed in 15.7.8, 14.8.8, 26.6)
CVE-2026-43756
5.5 - Medium
- July 27, 2026
A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data.
AuthZ
Apple iOS/macOS: Permission Bypass allows delete of unauthorized files (fixed before 26.6)
CVE-2026-64707
5.5 - Medium
- July 27, 2026
A permissions issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6. An app may be able to delete files for which it does not have permission.
Incorrect Permission Assignment for Critical Resource
Info Leak via Entitlement Bypass in macOS Sequoia 15.7.8
CVE-2026-64711
5.5 - Medium
- July 27, 2026
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to leak sensitive user information.
AuthZ
iOS 26.6 Authorization flaw allows contact addition without permission
CVE-2026-64746
9.8 - Critical
- July 27, 2026
An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. An app may be able to add contacts without user authorization.
AuthZ
macOS bug may cause app crash in Sequoia 15.7.8/Sonoma 14.8.8/Tahoe 26.6
CVE-2026-43767
5 - Medium
- July 27, 2026
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
Buffer Overflow
macOS Kernel Mem Corrupt via App (Sequoia 15.7.8 / Sonoma 14.8.8 / Tahoe 26.6)
CVE-2026-64697
9.8 - Critical
- July 27, 2026
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
Buffer Overflow
macOS Memory Corruption via App (pre-14.8.8)
CVE-2026-28911
9.8 - Critical
- July 27, 2026
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to corrupt memory of a system process.
Buffer Overflow
Apple iOS/macOS Permission Fault Enabling Fingerprinting, fixed 26.6
CVE-2026-43730
9.8 - Critical
- July 27, 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to fingerprint the user.
Information Disclosure
macOS Sandbox Bypass in macOS Tahoe 26.6 Allows App Data Access
CVE-2026-43819
5.5 - Medium
- July 27, 2026
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.6. An app may be able to access sensitive user data.
Authorization
macOS Stack Overflow (DoS) Fixed in Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.6
CVE-2026-43771
7.1 - High
- July 27, 2026
A stack overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial-of-service.
Stack Overflow
macOS file parser OOB read fixed in 15.7.8,14.8.8,26.6
CVE-2026-43747
7.1 - High
- July 27, 2026
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Parsing a maliciously crafted file may lead to an unexpected app termination.
Out-of-bounds Read
Apple OS NFS Client Buffer Overflow Kernel Mem Corruption, Fixed 26.6
CVE-2026-28931
8.8 - High
- July 27, 2026
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. Connecting to a malicious NFS server may lead to kernel memory corruption.
Classic Buffer Overflow
macOS Kernel Memory Corruption Fixed in Sequoia 15.7.8, Sonoma 14.8.8
CVE-2026-43710
9.8 - Critical
- July 27, 2026
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker may be able to cause unexpected system termination or corrupt kernel memory.
Buffer Overflow
macOS Path Handling Issue Allows Sandbox Escape (Fixed in 15.7.8/26.6)
CVE-2026-64731
9.8 - Critical
- July 27, 2026
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.
Directory traversal
Apple OS integer overflow: vulnerable pre-26.6 on iOS, iPadOS, macOS, tvOS
CVE-2026-64766
7.8 - High
- July 27, 2026
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
Integer Overflow or Wraparound
Apple iOS/macOS 26.6: OOB Write Fixed Remote Attacker Termination Risk
CVE-2026-43803
9.8 - Critical
- July 27, 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to cause unexpected system termination.
Memory Corruption
macOS Privilege Escalation via Permission Issue (fixed 15.7.8,14.8.8,26.6)
CVE-2026-39875
7.8 - High
- July 27, 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
Incorrect Default Permissions
Apple OS OOB Write (CVE-2026-64770): Fixed in iOS 26.6
CVE-2026-64770
9.8 - Critical
- July 27, 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
Memory Corruption
macOS & tvOS Pre-26.6 Type Confusion App-Induced System Crash
CVE-2026-64727
9.8 - Critical
- July 27, 2026
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.6, tvOS 26.6. An app may be able to cause unexpected system termination.
Object Type Confusion
Safari Authorization Flaw Pre-26.6 Allows App Access to Sensitive Data
CVE-2026-43792
6.5 - Medium
- July 27, 2026
An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.
AuthZ
macOS Sequoia 15.7.8 ENV Variable Validation Failure Leads to System Termination
CVE-2026-43793
9.8 - Critical
- July 27, 2026
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
Improper Input Validation
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Apple macOS or by Apple? Click the Watch button to subscribe.