Executive brief
A vulnerability in the macOS Crash Reporter component could allow a malicious application to gain full administrative (root) control over a computer. Crash Reporter is a system service that handles diagnostic information when applications fail. If exploited, an attacker could bypass security protections to access sensitive data, install persistent malware, or modify system settings.
Technical details
A race condition exists within the macOS Crash Reporter component. The vulnerability stems from insufficient validation during the handling of crash reports or diagnostic data. A local malicious application can exploit this timing window to escalate its privileges to root. Apple addressed the issue by implementing additional validation logic to ensure secure state handling. The fix is available in macOS Sequoia 15.7 and macOS Tahoe 26.
Affected products
- Apple macOS Sequoia Before 15.7
- Apple macOS Tahoe Before 26
Timeline
- 2025-09-15: patched: Initial release of macOS Sequoia 15.7 and Tahoe 26
- 2026-05-26: disclosed: CVE published and advisory updated with specific details