Executive brief
A security vulnerability exists in macOS that can cause applications to crash unexpectedly. This occurs when the system attempts to process a specifically designed malicious file. An exploit could lead to service interruptions or loss of unsaved work, though it does not appear to allow for data theft or unauthorized access.
Technical details
An out-of-bounds read vulnerability exists in macOS Sequoia, Sonoma, and Tahoe during the parsing of specially crafted files. The root cause is insufficient bounds checking when processing file content. An attacker can exploit this by tricking a user into opening a malicious file, leading to a denial-of-service (DoS) condition via application termination. Apple has addressed this issue by improving bounds checking in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Affected products
- Apple macOS Sequoia before 15.7.8
- Apple macOS Sonoma before 14.8.8
- Apple macOS Tahoe before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched