CVE-2026-86901

Apple · macOS

A local attacker can cause system termination or kernel memory disclosure by mounting a maliciously crafted exFAT volume due to an out-of-bounds write vulnerability.

Executive summary

An out-of-bounds write vulnerability in Apple macOS allows a local user to cause system crashes or disclose sensitive kernel memory by mounting a malicious exFAT volume.

Vulnerability

This vulnerability is an out-of-bounds write flaw within the exFAT filesystem driver, which can be triggered by a local user with low privileges. By mounting a specially crafted exFAT volume, an attacker can induce unexpected system termination or gain unauthorized access to kernel memory.

Business impact

The potential for kernel memory disclosure poses a significant risk to data confidentiality, as attackers may extract sensitive information handled by the operating system. Furthermore, the ability to cause unexpected system termination threatens service availability, potentially leading to operational disruption. Given the CVSS score of 7.1, this is classified as a high-severity issue that requires timely remediation to prevent unauthorized data access.

Remediation

Immediate Action: Update all affected Apple macOS systems to version 27 or later, which contains the improved bounds checking necessary to mitigate this flaw.

Proactive Monitoring: Security teams should monitor system logs for unusual kernel events or repeated system crashes associated with external storage device mounting.

Compensating Controls: Restrict the ability of non-administrative users to mount external storage volumes on sensitive workstations or servers until the patch is applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a significant risk to system integrity and data security. Organizations should prioritize patching macOS endpoints to version 27 to neutralize the risk of kernel memory exposure and system instability. Failure to update leaves systems susceptible to local exploitation, which could be leveraged to escalate privileges or exfiltrate sensitive kernel data.

More Apple CVEs all →

History

CVE Brief tracked this CVE 3 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.1 (3.1)
  4. Analyst report written

Sources