Back to overview

CVE-2026-64745

LOW
2.4
CVSS 3.1
Description
This issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A person with physical access to a locked device may be able to access contacts and photos.

Metadata

CVE ID
CVE-2026-64745
State
PUBLISHED
Assigner
apple
Reserved
2026-07-20 18:10 UTC
Published
2026-07-27 20:12 UTC
Last updated
2026-07-28 14:37 UTC
Primary CWE
CWE-287
CWE-287 Improper Authentication
Vendor / Product
Apple / macOS
Sources
cve.org  ·  NVD

Severity & Metrics

2.4 LOW CVSS 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Apple macOS 0 < 15.7.8, 0 < 26.6
Weakness (CWE)
CWESourceDescription
cna A person with physical access to a locked device may be able to access contacts and photos
CWE-287 adp CWE-287 Improper Authentication
CVSS scores (1)
ScoreSeverityVersionSourceVector
2.4 LOW 3.1 adp CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Back to overview