Junglewise Threat Intelligence

CVE-2026-64707: Apple iOS and macOS improper permission validation allows file deletion

CVE-2026-64707 · Severity: info · Published 2026-07-27

Technologies: Apple macOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A security issue in Apple operating systems could allow a malicious application to delete files it should not have access to. This affects iPhones, iPads, Macs, and Vision Pro headsets. If exploited, this could lead to the loss of important user data or system files. Apple has released software updates to address this by improving how the system validates file permissions.

Technical details

A permissions vulnerability exists across multiple Apple operating systems due to insufficient validation of file access requests. A locally installed malicious application could exploit this flaw to bypass standard permission checks and delete arbitrary files on the filesystem. The vulnerability was addressed by implementing improved validation logic within the affected components. The fix is available in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, and visionOS 26.6.

Affected products

  • Apple iOS and iPadOS < 26.6
  • Apple macOS Sonoma < 14.8.8
  • Apple macOS Sequoia < 15.7.8
  • Apple macOS Tahoe < 26.6
  • Apple visionOS < 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats