CVE-2026-64705: Buffer Overflow
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7. An app may be able to cause unexpected system termination or write kernel memory.
Other sources
Accessibility. This issue was addressed through improved state management.
— Apple
APFS. A buffer overflow was addressed with improved bounds checking.
— Apple
AppleJPEG. A memory corruption issue was addressed with improved input validation.
— Apple
Audio. The issue was addressed with improved memory handling.
— Apple
CoreMedia. This issue was addressed through improved state management.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.8.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.7.7
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-28959
- CVE-2026-28956
- CVE-2026-39869
- CVE-2026-28922
- CVE-2026-28936
- CVE-2026-28915
- CVE-2026-43659
- CVE-2026-28923
- CVE-2026-64705
- CVE-2026-28925
- CVE-2025-43524
- CVE-2026-28977
- CVE-2026-28990
- CVE-2026-28978
- CVE-2026-28992
- CVE-2026-28943
- CVE-2026-28969
- CVE-2026-43654
- CVE-2026-28954
- CVE-2026-28897
- CVE-2026-28952
- CVE-2026-28908
- CVE-2026-28951
- CVE-2026-28972
- CVE-2026-28986
- CVE-2026-28987
- CVE-2026-28929
- CVE-2026-43653
- CVE-2026-43668
- CVE-2026-43666
- CVE-2026-28906
- CVE-2026-28840
- CVE-2026-28912
- CVE-2026-43656
- CVE-2026-39870
- CVE-2026-28846
- CVE-2026-28993
- CVE-2026-28996
- CVE-2026-28919
- CVE-2026-28924
- CVE-2026-39871
- CVE-2026-28819
- CVE-2026-28994
- CVE-2026-28920
- CVE-2026-64732
- CVE-2026-28878
- CVE-2026-28940
- CVE-2026-28941
- CVE-2026-28848
- CVE-2026-28974
Frequently Asked Questions
Which systems should be prioritized for updating?
Systems running macOS Sequoia earlier than 15.7.7 or macOS Sonoma earlier than 14.8.7 should be prioritized. The fixes cover multiple components, including Accessibility, APFS, AppleJPEG, Audio, CoreMedia, CoreServices, CUPS, FileProvider, GPU Drivers, HFS, and Crash Reporter.
What could successful exploitation allow?
The available information states that an app may be able to cause unexpected system termination or write kernel memory. Other addressed issues include memory corruption, race conditions, path parsing, sensitive-data exposure in crash reporting, and insufficient log redaction.
What attacker access is indicated by the available information?
The description specifically identifies an app as the potential source of exploitation for the unexpected termination or kernel-memory-write issue. It does not state whether remote access, user interaction, elevated privileges, or a particular default configuration is required.