CVE-2026-84581
Apple · macOS
A buffer overflow vulnerability in Apple macOS allows for kernel memory corruption or system termination when mounting a maliciously crafted disk image.
Executive summary
A critical buffer overflow vulnerability in Apple macOS allows unauthenticated attackers to corrupt kernel memory or crash the system by leveraging malicious disk images.
Vulnerability
This vulnerability is a buffer overflow resulting from improper bounds checking when processing disk images. The issue permits an unauthenticated local attacker to trigger memory corruption or system termination.
Business impact
The ability to corrupt kernel memory poses a severe risk to system integrity and availability. An attacker could potentially achieve unauthorized code execution at the kernel level, leading to complete system compromise, data theft, or persistent denial of service. Given the CVSS score of 8.4, this vulnerability is categorized as high severity and requires immediate attention to prevent potential exploitation.
Remediation
Immediate Action: Update all affected macOS installations to the patched versions: macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27.
Proactive Monitoring: Monitor system logs for unexpected crashes or kernel panic events that coincide with the mounting of external media or disk images.
Compensating Controls: Restrict the ability of non-privileged users to mount external disk images via system policy or mobile device management (MDM) configurations until updates can be applied.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability presents a significant risk to the stability and security of macOS environments. System administrators should prioritize the deployment of the specified macOS updates across all enterprise endpoints. Failure to patch these systems leaves them susceptible to kernel-level attacks that could bypass standard security protections.
More Apple CVEs all →
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.4 (3.1)
- Analyst report written