CVE-2026-64707
Analyzed Analyzed - Analysis Complete

Improper File Deletion in Apple iOS and macOS

Vulnerability report for CVE-2026-64707, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-28

Assigner: Apple Inc.

Description

A permissions issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6. An app may be able to delete files for which it does not have permission.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-28
Generated
2026-08-17
AI Q&A
2026-07-28
EPSS Evaluated
2026-08-15
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
apple macos From 14.0 (inc) to 14.8.8 (exc)
apple macos From 15.0 (inc) to 15.7.8 (exc)
apple macos From 26.0 (inc) to 26.6 (exc)
apple ipados to 26.6 (exc)
apple iphone_os to 26.6 (exc)
apple visionos to 26.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a permissions issue in Apple operating systems where an app could delete files it does not have permission to access. It was addressed with improved validation in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, and visionOS 26.6.

Detection Guidance

This vulnerability involves an app deleting files without proper permissions. Detection requires checking for unauthorized file deletions, especially in system directories. Monitor logs for suspicious file operations and review installed apps with excessive permissions. No specific commands are provided in the context.

Impact Analysis

This vulnerability could allow malicious apps to delete important files on your device, including personal data or system files, potentially causing data loss or system instability.

Compliance Impact

The provided CVE does not specify direct impacts on compliance with GDPR, HIPAA, or other standards. The vulnerability involves an app potentially deleting unauthorized files, which could lead to data loss or unauthorized access, potentially affecting compliance if sensitive data is involved. However, no explicit details are provided.

Mitigation Strategies

Update affected systems to the fixed versions: iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, or visionOS 26.6. This addresses the permissions validation issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64707. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart