CRITICALVulnerability

CVE-2026-64740

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. A malicious app may be able to break out of its sandbox.

Properties

severity
CRITICAL
score
9.3
cve_id
CVE-2026-64740
vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
published_at
2026-07-27T21:17:12.877
last_modified
2026-08-17T22:17:19.520

Related Entities (6)

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (4)

[Product]
[Product]
[Product]
[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-64740 — Ninja Signal Threat Intelligence | Ninja Signal