A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. A malicious app may be able to break out of its sandbox.
Problem type
- A malicious app may be able to break out of its sandbox
Affected products
Apple
< 26.6 - AFFECTED
< 14.8.8 - AFFECTED
< 15.7.8 - AFFECTED
< 26.6 - AFFECTED
< 26.6 - AFFECTED
References
https://support.apple.com/en-us/128066
https://support.apple.com/en-us/128067
https://support.apple.com/en-us/128069
https://support.apple.com/en-us/128071
https://support.apple.com/en-us/128072
GitHub Security Advisories
GHSA-fv3r-47cp-xc8h
A parsing issue in the handling of directory paths was addressed with improved path validation....
https://github.com/advisories/GHSA-fv3r-47cp-xc8hA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. A malicious app may be able to break out of its sandbox.
https://nvd.nist.gov/vuln/detail/CVE-2026-64740
https://support.apple.com/en-us/128066
https://support.apple.com/en-us/128067
https://support.apple.com/en-us/128069
https://support.apple.com/en-us/128071
https://support.apple.com/en-us/128072
https://github.com/advisories/GHSA-fv3r-47cp-xc8h
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-64740Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-64740",
"assignerOrgId": "286789f9-fbc2-4510-9f9a-43facdede74c",
"assignerShortName": "apple",
"dateUpdated": "2026-07-28T14:16:12.493Z",
"dateReserved": "2026-07-20T18:09:54.848Z",
"datePublished": "2026-07-27T20:14:53.836Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "286789f9-fbc2-4510-9f9a-43facdede74c",
"shortName": "apple",
"dateUpdated": "2026-07-27T20:14:53.836Z"
},
"descriptions": [
{
"lang": "en",
"value": "A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. A malicious app may be able to break out of its sandbox."
}
],
"affected": [
{
"vendor": "Apple",
"product": "iOS and iPadOS",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "custom",
"lessThan": "26.6"
}
]
},
{
"vendor": "Apple",
"product": "macOS",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "custom",
"lessThan": "14.8.8"
},
{
"version": "0",
"status": "affected",
"versionType": "custom",
"lessThan": "15.7.8"
},
{
"version": "0",
"status": "affected",
"versionType": "custom",
"lessThan": "26.6"
}
]
},
{
"vendor": "Apple",
"product": "tvOS",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "custom",
"lessThan": "26.6"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "A malicious app may be able to break out of its sandbox"
}
]
}
],
"references": [
{
"url": "https://support.apple.com/en-us/128066"
},
{
"url": "https://support.apple.com/en-us/128067"
},
{
"url": "https://support.apple.com/en-us/128069"
},
{
"url": "https://support.apple.com/en-us/128071"
},
{
"url": "https://support.apple.com/en-us/128072"
}
]
},
"adp": [
{
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2026-07-28T14:16:12.493Z"
},
"title": "CISA ADP Vulnrichment",
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
"cweId": "CWE-22",
"type": "CWE"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL"
}
},
{}
]
}
]
}
}