SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-64740

CRITICAL · CVSS 9.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

A critical vulnerability exists in the handling of directory paths, allowing a malicious app to potentially escape its sandbox environment. This could lead to unauthorized access to sensitive data or system resources. Users and organizations utilizing iOS, iPadOS, macOS, and tvOS should prioritize updating to the latest versions to mitigate this risk.

CVE
CVE-2026-64740
Severity
CRITICAL
CVSS
9.3
EPSS
0.22%

Original NVD Description

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. A malicious app may be able to break out of its sandbox.

Related CVEs

Other vulnerabilities affecting the same vendor(s)