CVE-2026-64778
Apple has resolved vulnerabilities in macOS Tahoe 26.6.2. The vulnerabilities involve multiple aspects of memory management, input validation and state management within Apple's operating systems and Safari browser. A number of vulnerabilities allow a malicious actor to cause memory corruption by processing specially crafted web content or images, which can lead to unexpected crashes, system termination or leaking of sensitive user information. Other vulnerabilities involve use-after-free conditions and out-of-bounds memory access, which can also result in system instability or exposure of kernel memory. The problems exist in the mechanisms that control app access to user data, the processing of web content and the handling of images. By applying improved validation, memory management and locking mechanisms, Apple prevents these vulnerabilities from being exploited to cause crashes, denial-of-service or unauthorized information exposure.
CSIRTS triage
- What
- Multiple memory management and validation flaws including use-after-free, out-of-bounds access, and memory corruption triggered by malicious web content or images.
- Who is affected
- macOS Tahoe 26.6.2 users and systems processing untrusted web content or images.
- Urgency
- High priority; vulnerabilities lead to unexpected crashes, kernel memory leaks, and potential denial of service.
- Action
- Update macOS to the patched version addressing CVE-2026-65339, CVE-2026-65347, CVE-2026-65346, CVE-2026-64788, CVE-2026-65343, CVE-2026-65349, CVE-2026-65330, and CVE-2026-64784.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-64778
Get an email if CVE-2026-64778 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownNCSC-2026-0317 [1.00] [M/H] Vulnerabilities resolved in Apple macOSncsc-nl · 2026-08-20
- mediumCVE-2026-64778: The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.1…nvd · 2026-08-17
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-64778)