Executive brief
A vulnerability in the HFS file system component of macOS could allow a malicious application to crash the computer or modify sensitive kernel memory. This could lead to a complete system takeover or permanent data loss. Users should update to the latest versions of macOS Sequoia, Sonoma, or Tahoe to protect their systems.
Technical details
A buffer overflow vulnerability exists in the HFS (Hierarchical File System) component of macOS. The flaw is caused by insufficient bounds checking when processing certain inputs. A local malicious application can exploit this vulnerability to trigger a kernel-level buffer overflow, potentially leading to arbitrary kernel memory writes or a kernel panic (denial of service). Apple addressed the issue by improving bounds checking in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5.
Affected products
- Apple macOS Sequoia before 15.7.7
- Apple macOS Sonoma before 14.8.7
- Apple macOS Tahoe before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory