---
id: CVE-2026-64705
title: A buffer overflow was addressed with improved bounds checking
summary: >-
  A buffer overflow was addressed with improved bounds checking. This issue is
  fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7,
  macOS Tahoe 26.6. An app may be able to cause unexpected system termination or
  wri…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-120
vendor: apple
product: macos
affected:
  - 'macos >= 14.0, < 14.8.7'
  - 'macos >= 15.0, < 15.7.7'
patched:
  - macos 15.7.7
published: '2026-08-25'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T21:17:13.680'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64705'
references:
  - url: 'https://support.apple.com/en-us/127116'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/127117'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/128066'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/128067'
    label: product-security@apple.com
tags:
  - nvd
  - exploit-available
  - cve.org
epss: 0.00128
epssPercentile: 0.02787
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/eddinos2/CVE-2026-64705'
  checkedAt: '2026-09-23T07:14:34.638Z'
exploitAvailable: true
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-26T00:21:59.165867Z'
ingestedAt: '2026-09-14T21:15:17.518Z'
---

## Overview

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory.

## Affected

- `macos >= 14.0, < 14.8.7`
- `macos >= 15.0, < 15.7.7`

## Remediation

Upgrade past the affected range:

- `macos 15.7.7`
