Junglewise Threat Intelligence

CVE-2026-64699: Apple macOS kernel memory disclosure via memory initialization issue

CVE-2026-64699 · Severity: info · Published 2026-07-27

Technologies: Apple macOS Tahoe. Vendors: Apple.

Executive brief

A security vulnerability in macOS could allow a malicious application to access sensitive information stored in the computer's kernel memory. The kernel is the core part of the operating system that manages system resources and security; unauthorized access to its memory could lead to the disclosure of private system data. This issue affects macOS Sequoia, Sonoma, and Tahoe.

Technical details

A memory initialization vulnerability exists in the macOS kernel due to improper memory handling. A local attacker can exploit this by running a specially crafted application to read uninitialized kernel memory, potentially leading to the disclosure of sensitive system information. The issue was addressed by improving memory handling and initialization routines. Patches are available in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.

Affected products

  • Apple macOS Sequoia < 15.7.8
  • Apple macOS Sonoma < 14.8.8
  • Apple macOS Tahoe < 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats