Description
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an integer overflow that can be triggered by malformed input in certain macOS components. The overflow causes a crash of the system or affected application, resulting in an unexpected system termination. The impact is a denial of service that disrupts user sessions and can affect critical processes.

Affected Systems

The issue affects Apple macOS operating systems older than Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6. Versions before these releases are vulnerable; the problem is addressed in Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.6 and later updates.

Risk and Exploitability

The EPSS score of less than 1% and a CVSS score of 9.8 indicate a low probability of exploitation but a high potential impact. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The likelihood of remote exploitation appears low, as the attack likely requires local execution of an application that processes large integer inputs, yet the high severity underscores the need to apply the fix promptly.

Generated by OpenCVE AI on August 3, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest macOS update that includes the integer overflow fix (Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.6 or later).
  • Update or replace any third‑party software that parses large integers with older or vulnerable code libraries.
  • If an application cannot be updated immediately, restrict its execution permissions or quarantine it to prevent unexpected system termination.

Generated by OpenCVE AI on August 3, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow Leading to Unexpected System Termination in macOS

Wed, 29 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow Leading to Unexpected System Termination in macOS
Weaknesses CWE-190

Tue, 28 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:41:45.630Z

Reserved: 2026-07-20T18:09:01.158Z

Link: CVE-2026-64694

cve-icon Vulnrichment

Updated: 2026-07-28T14:41:35.715Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:09.097

Modified: 2026-07-28T17:58:33.637

Link: CVE-2026-64694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T16:30:04Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound