CVE-2026-28982

9.8

Apple · macOS

A race condition in macOS allows remote, unauthenticated attackers to trigger kernel memory corruption or cause system termination via improved locking failures.

Executive summary

A critical race condition in Apple macOS allows unauthenticated remote attackers to execute arbitrary code or crash the system, necessitating immediate patching.

Vulnerability

This is a race condition vulnerability resulting from improper locking mechanisms within the kernel. An unauthenticated remote attacker can leverage this flaw to corrupt kernel memory or force an unexpected system termination.

Business impact

The vulnerability carries a CVSS score of 9.8, reflecting its critical severity due to the lack of required authentication or user interaction. Successful exploitation permits an attacker to achieve total system compromise, potentially leading to unauthorized data access, complete loss of system availability, and the installation of persistent malicious software.

Remediation

Immediate Action: Update all affected macOS systems to macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, or macOS Tahoe 26.6 immediately.

Proactive Monitoring: Review system kernel logs for signs of instability, unexpected reboots, or memory access errors that may indicate exploitation attempts.

Compensating Controls: Ensure that network-level defenses, such as host-based firewalls and endpoint detection and response (EDR) solutions, are active to restrict exposure to untrusted network traffic.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical CVSS severity and the potential for kernel-level exploitation, this vulnerability poses a severe risk to organizational infrastructure. Security teams must prioritize patching all macOS endpoints to the specified versions or later to eliminate the risk of remote code execution and system instability.

More Apple CVEs

Sources