Directory Path Parsing Issue in Apple Products
CVE-2026-64740

9.3CRITICAL

Key Information:

Vendor

Apple

Vendor
CVE Published:
27 July 2026

What is CVE-2026-64740?

A vulnerability exists within Apple's products that arises from an improper parsing of directory paths. This flaw, if exploited by a malicious application, could potentially allow the app to break out of its intended sandbox environment, leading to unauthorized access to system resources or data. Apple has addressed this issue with enhanced path validation measures in the latest updates of its operating systems.

Affected Version(s)

iOS and iPadOS 0 < 18.7.10

iOS and iPadOS 0 < 26.6

macOS 0 < 14.8.8

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.