Junglewise Threat Intelligence

CVE-2026-28925: Apple macOS buffer overflow in HFS

CVE-2026-28925 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A vulnerability in the HFS file system component of macOS could allow a malicious application to crash the computer or modify sensitive kernel memory. This could lead to a complete system takeover or permanent data loss. Users should update to the latest versions of macOS Sequoia, Sonoma, or Tahoe to protect their systems.

Technical details

A buffer overflow vulnerability exists in the HFS (Hierarchical File System) component of macOS. The flaw is caused by insufficient bounds checking when processing certain inputs. A local malicious application can exploit this vulnerability to trigger a kernel-level buffer overflow, potentially leading to arbitrary kernel memory writes or a kernel panic (denial of service). Apple addressed the issue by improving bounds checking in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5.

Affected products

  • Apple macOS Sequoia before 15.7.7
  • Apple macOS Sonoma before 14.8.7
  • Apple macOS Tahoe before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats