Junglewise Threat Intelligence

CVE-2026-20679: Apple macOS CoreUI malformed file denial of service

CVE-2026-20679 · Severity: medium · CVSS 4.3 · Published 2026-08-21

Technologies: Apple macOS Sonoma. Vendors: Apple.

Executive brief

CoreUI is a system framework used by macOS applications to render user interface elements and graphics. Processing a maliciously crafted file can cause an application using CoreUI to crash unexpectedly, disrupting user work and potentially impacting system stability. An attacker could exploit this by distributing a crafted file (such as an image or document) to cause denial-of-service conditions on affected systems.

Technical details

CVE-2026-20679 is a denial-of-service vulnerability in Apple's CoreUI framework stemming from insufficient input validation when processing maliciously crafted files. The vulnerability allows an attacker to trigger an unexpected application termination by providing a specially constructed file that bypasses CoreUI's existing checks. The attack vector is local/adjacent (file-based delivery), with no authentication requirements—the user simply needs to open the malicious file. The fix involved adding improved checks to properly validate file inputs before processing. Patches are available in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4.

Affected products

  • Apple macOS Sequoia 15.7.5 and earlier
  • Apple macOS Sonoma 14.8.5 and earlier
  • Apple macOS Tahoe 26.4 and earlier

Timeline

  • 2026-08-21: disclosed: CVE-2026-20679 published
  • 2026-03-24: patched: Fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4

References

Related threats