Description
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The macOS memory‑handling flaw is a buffer‑overflow weakness (CWE‑119) that can be triggered by a remote user. It corrupts kernel memory and can cause the operating system to terminate unexpectedly, resulting in a denial‑of‑service condition at the kernel level. The description does not indicate that the attacker gains code‑execution or elevated privileges, so the impact is limited to crash and loss of availability.

Affected Systems

Apple’s macOS is impacted in all releases that do not include the update for Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6. Versions older than or equivalent to those builds remain vulnerable until the corresponding patch is applied.

Risk and Exploitability

The flaw is remotely exploitable as indicated by its description. The CVSS score of 9.8 signals critical severity, while an EPSS score of <1% indicates a very low yet non‑zero likelihood of exploitation. It is not listed in the CISA KEV catalog. Successful exploitation corrupts kernel memory and can cause system termination, effectively creating a high‑availability disruption. The likely attack vector is through a network‑based service that accepts untrusted input, though the CVE description does not specify a particular protocol, so this inference is based on standard remote memory‑corruption patterns.

Generated by OpenCVE AI on August 4, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the macOS update that includes the memory‑handling fix for Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6.
  • Reboot the system after the update so that kernel changes take effect.
  • If immediate update is not possible, restrict exposure by disabling remote management or other network‑based services that could trigger the flaw until the patch is applied.

Generated by OpenCVE AI on August 4, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Kernel Memory Corruption Leading to System Termination in macOS

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Remote Memory Corruption Leading to System Termination in macOS
Weaknesses CWE-120
CWE-122

Thu, 30 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Remote Memory Corruption Leading to System Termination in macOS
Weaknesses CWE-120
CWE-122

Tue, 28 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T15:58:50.760Z

Reserved: 2026-07-20T18:09:01.158Z

Link: CVE-2026-64696

cve-icon Vulnrichment

Updated: 2026-07-28T15:58:40.616Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:09.290

Modified: 2026-07-28T17:58:18.120

Link: CVE-2026-64696

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:30:10Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer