Executive brief
A buffer overflow vulnerability in macOS affects how the system handles malicious disk images. When a user mounts a specially crafted disk image, the system may crash unexpectedly. This vulnerability has been patched in recent macOS updates and no active exploitation has been reported.
Technical details
A buffer overflow vulnerability (CVE-2026-28934) exists in Apple's AppleDouble component, which handles disk image mounting. The vulnerability is an out-of-bounds write issue in the disk image parsing logic. An attacker must craft a malicious disk image file and convince a user to mount it; no network access or elevated privileges are required for exploitation. A successful exploit causes unexpected process termination (denial of service). The vulnerability has been patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed: CVE-2026-28934 published; patches released in macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.7