CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64740

criticalCVSS 9.3covered by 1 sourcefirst seen 2026-07-27
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. A malicious app may be able to break out of its sandbox.

⚡ Watch CVE-2026-64740

Get an email if CVE-2026-64740 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-64740

CVE.org record

Embed the live status

CVE-2026-64740 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64740 status](https://www.csirts.com/badge/CVE-2026-64740)](https://www.csirts.com/cve/CVE-2026-64740)