Executive brief
A memory corruption vulnerability in macOS could allow a malicious application to cause a system crash or denial of service. This issue affects the core operating system and could disrupt user operations or system stability. Apple has released security updates for macOS Sequoia, Sonoma, and Tahoe to address this flaw.
Technical details
A logic vulnerability exists in macOS that leads to memory corruption due to improper state management. An attacker-controlled application can exploit this flaw to trigger a denial of service (DoS) condition. The vulnerability requires the execution of a malicious app on the target system (local attack vector). Apple addressed the root cause by improving state management within the affected component. Patches are available in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Affected products
- Apple macOS Sequoia before 15.7.8
- Apple macOS Sonoma before 14.8.8
- Apple macOS Tahoe before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory
- 2026-07-27: patched