File Access Vulnerability in Apple Container Software
CVE-2026-64777

4.3MEDIUM

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-64777?

A security vulnerability in Apple Container allows malicious builder peers to request in-context files by name from the host system. This can lead to unauthorized access to sensitive files, which may reside outside the expected build context. The issue has been resolved in version 1.2.0 of the container software, emphasizing the importance of keeping software up-to-date to mitigate risks associated with unauthorized file access.

Affected Version(s)

container 0 < 1.2.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.