Junglewise Threat Intelligence

CVE-2026-28934: Apple macOS buffer overflow in disk image mounting

CVE-2026-28934 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A buffer overflow vulnerability in macOS affects how the system handles malicious disk images. When a user mounts a specially crafted disk image, the system may crash unexpectedly. This vulnerability has been patched in recent macOS updates and no active exploitation has been reported.

Technical details

A buffer overflow vulnerability (CVE-2026-28934) exists in Apple's AppleDouble component, which handles disk image mounting. The vulnerability is an out-of-bounds write issue in the disk image parsing logic. An attacker must craft a malicious disk image file and convince a user to mount it; no network access or elevated privileges are required for exploitation. A successful exploit causes unexpected process termination (denial of service). The vulnerability has been patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed: CVE-2026-28934 published; patches released in macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.7

References

Related threats