CVE-2026-84512
Apple · macOS
A buffer overflow vulnerability in macOS allows attackers to cause system termination or kernel memory corruption via a maliciously crafted disk image.
Executive summary
A high-severity buffer overflow vulnerability in Apple macOS, triggered by mounting a malicious disk image, could lead to system crashes or arbitrary code execution.
Vulnerability
This vulnerability is a buffer overflow flaw resulting from improper bounds checking during the processing of disk images. It is an unauthenticated vulnerability requiring user interaction to mount the malicious file.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high risk of significant system compromise. Successful exploitation allows an attacker to corrupt kernel memory, which may lead to unauthorized system control, data exposure, or total service disruption. Organizations relying on macOS for critical operations face potential operational downtime and integrity loss if users are tricked into mounting malicious disk images.
Remediation
Immediate Action: Update all affected macOS systems to the fixed versions (15.8, 26.7, or 27) immediately to resolve the underlying buffer overflow.
Proactive Monitoring: Monitor system logs for unexpected kernel panics or repeated crashes associated with disk mounting processes.
Compensating Controls: Implement endpoint security policies that restrict the mounting of unauthorized disk images and utilize security software capable of scanning external media for malicious payloads.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the severity of potential kernel memory corruption, organizations should prioritize patching these macOS versions across all managed endpoints. Users should be cautioned against mounting disk images from untrusted or unverified sources until updates are fully deployed, as the vulnerability relies on user interaction to facilitate the attack.
More Apple CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written