
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-64776 is a kernel memory disclosure vulnerability in the Disk Images component of Apple macOS. Due to improper bounds checks, a local application can read and disclose kernel memory contents. The vulnerability affects macOS Sonoma versions prior to 14.8.8, macOS Sequoia versions prior to 15.7.8, and macOS Tahoe versions prior to 26.6. It was disclosed and patched on July 27, 2026. The CVSS category is estimated as Medium, with an EPSS score of 0.0 at time of publication. The vulnerability was discovered by Hyunwoo Kim (@v4bel) (Apple Advisory Tahoe, Apple Advisory Sequoia, Apple Advisory Sonoma, Github Advisory).
The vulnerability resides in the Disk Images subsystem of macOS and stems from insufficient bounds checking (CWE class: improper bounds checking), allowing an application to read memory outside of intended boundaries within the kernel address space. An attacker with the ability to run a local application on the affected system can trigger this flaw to read arbitrary kernel memory. No authentication bypass or special privileges are required beyond the ability to execute code on the target system. Apple addressed the issue by implementing improved bounds checks in the affected component (Apple Advisory Tahoe, Apple Advisory Sequoia, Apple Advisory Sonoma).
Successful exploitation allows any application running on the affected macOS system to disclose arbitrary kernel memory contents, potentially exposing sensitive data such as cryptographic keys, authentication tokens, and other privileged kernel-resident information. The impact is primarily a confidentiality breach; integrity and availability of the system are not directly affected by this vulnerability. While the vulnerability itself does not grant code execution or privilege escalation, leaked kernel memory could be leveraged as a stepping stone in a chained exploit to bypass ASLR or other kernel protections (Apple Advisory Tahoe, Github Advisory).
Apple has released patches addressing this vulnerability in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6, all released on July 27, 2026. Users should update their macOS systems to one of these versions immediately via System Settings > General > Software Update. No configuration-based workarounds have been published by Apple; updating to a patched version is the only recommended remediation (Apple Advisory Tahoe, Apple Advisory Sequoia, Apple Advisory Sonoma).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."