Threat Advisory

macOS HFS + Vulnerability Allows Malformed Disk Image to Crash System

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-43682 with a CVSS score of 9.8 affects Apple macOS through a critical kernel heap overflow vulnerability in the HFS+ file system driver. The flaw was reproduced on Apple silicon and allows a remote user to cause unexpected system termination or corrupt kernel memory through a malformed disk image containing files' extended attributes which can trigger a kernel panic. The vulnerability can result in data corruption and system crashes. Patches are available and users should update their systems immediately to prevent exploitation.

RECOMMENDATIONS:

  • We recommend you to update Apple macOS to below version:
  • macOS Tahoe to version 26.6 or later.
  • macOS Sequoia to version 15.7.8 or later.
  • macOS Sonoma to version 14.8.8 or later.

REFERENCES:

The following reports contain further technical details:[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-43682 with a CVSS score of 9.8 affects Apple macOS through a critical kernel heap overflow vulnerability in the HFS+ file system driver. The flaw was reproduced on Apple silicon and allows a remote user to cause unexpected system termination or corrupt kernel memory through a malformed disk image containing files' extended attributes which can trigger a kernel panic. The vulnerability can result in data corruption and system crashes. Patches are available and users should update their systems immediately to prevent exploitation.

RECOMMENDATIONS:

  • We recommend you to update Apple macOS to below version:
  • macOS Tahoe to version 26.6 or later.
  • macOS Sequoia to version 15.7.8 or later.
  • macOS Sonoma to version 14.8.8 or later.

REFERENCES:

The following reports contain further technical details:[emaillocker id="1283"]

[/emaillocker]
crossmenu