CVE-2026-64701: High severity vulnerability
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
macOS Sequoiato a version that resolves this vulnerability.Fixed in 15.7.8 - Upgrade
Upgrade
macOS Tahoeto a version that resolves this vulnerability.Fixed in 26.6
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker would need to run a malicious application on the affected Mac. The CVSS vector indicates local access, low attack complexity, and low privileges are required; no user interaction is required.
What is the impact if exploitation succeeds?
A malicious app may gain root privileges, resulting in high impact to confidentiality, integrity, and availability.
Which updates contain the fix?
The issue is fixed in macOS Sequoia 15.7.8 and macOS Tahoe 26.6.