Executive brief
AppleRAID is a macOS component responsible for managing software RAID disk configurations. An out-of-bounds write vulnerability in this component allows an attacker to trigger unexpected system termination by mounting a specially crafted malicious disk image. This could lead to system crashes and potential data loss or corruption.
Technical details
An out-of-bounds write issue exists in Apple's AppleRAID component, a kernel-level storage subsystem. The vulnerability is triggered when processing a maliciously crafted disk image, causing memory corruption due to insufficient bounds checking. The attack vector requires a local user capable of mounting disk images; exploitation results in denial-of-service through unexpected system termination. The flaw was addressed with improved bounds checking in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Affected products
- Apple macOS Sequoia before 15.7.8
- Apple macOS Sonoma before 14.8.8
- Apple macOS Tahoe before 26.6
Timeline
- 2026-09-14: disclosed: CVE-2026-43761 published
- 2026-07-27: patched: Fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6