Executive brief
A security vulnerability in the macOS kernel could allow a malicious application to modify protected parts of the file system or cause a system-wide denial of service. This bypasses standard security protections intended to keep core system files safe from unauthorized changes. If exploited, this could lead to system instability or unauthorized persistent changes to the operating system.
Technical details
A vulnerability exists in the macOS Kernel that allows a local application to modify protected areas of the file system and trigger a denial of service. While the specific vulnerability class is described by Apple as a 'denial of service issue,' the impact includes the ability to bypass file system protections. The issue was addressed by removing the vulnerable code in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5. Exploitation requires a malicious application to be running on the target system.
Affected products
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched