CVE-2026-43682 with a CVSS score of 9.8 affects Apple macOS through a critical kernel heap overflow vulnerability in the HFS+ file system driver. The flaw was reproduced on Apple silicon and allows a remote user to cause unexpected system termination or corrupt kernel memory through a malformed disk image containing files' extended attributes which can trigger a kernel panic. The vulnerability can result in data corruption and system crashes. Patches are available and users should update their systems immediately to prevent exploitation.
The following reports contain further technical details:[/subscribe_to_unlock_form]
CVE-2026-43682 with a CVSS score of 9.8 affects Apple macOS through a critical kernel heap overflow vulnerability in the HFS+ file system driver. The flaw was reproduced on Apple silicon and allows a remote user to cause unexpected system termination or corrupt kernel memory through a malformed disk image containing files' extended attributes which can trigger a kernel panic. The vulnerability can result in data corruption and system crashes. Patches are available and users should update their systems immediately to prevent exploitation.
The following reports contain further technical details:[emaillocker id="1283"]
[/emaillocker]