CVE-2026-64691Published 50 days ago. NVD backfills CPE data for days or weeks after publication, and OSV and the exploit indexes lag too. Scope and status here may change.
A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
CWE-120
No public exploit
Nothing published shows this CVE being exploited, which is not the same as ruling it out.
CVSS E:U
Not a Java vulnerability. Outside ARMR's domain entirely.
| Decided by | non-java-upstream : A root cause in non-Java code: an OS kernel, a C library, or a bundled runtime |
|---|---|
| Finding | Root cause is in an ignored upstream product (Apple/macOS). Common reasons: not a Java library, vulnerability is in native/C code, or product is outside ARMR's mitigation scope. |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 metric
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CISA-ADP | Secondary | published |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | apple | macos | generic | ≥ 26.0 and < 26.6 |
| URL | Tags |
|---|---|
| https://support.apple.com/en-us/128067 | Release Notes, Vendor Advisory |
| Published | 2026-07-27 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-07-28 | NVD's own last-modified date for this record. |