Executive brief
A vulnerability in macOS could allow a malicious application to cause the entire computer to crash or shut down unexpectedly. This issue stems from how the operating system handles specific internal settings known as environment variables. Apple has released software updates to correct this behavior and prevent such system instability.
Technical details
A vulnerability exists in the macOS kernel or system libraries related to the improper validation of environment variables. A local application can exploit this flaw by passing specially crafted environment variables, leading to a denial-of-service (DoS) condition via unexpected system termination. The vulnerability was mitigated by implementing improved input validation for environment variables. Affected versions include macOS Sequoia prior to 15.7.8, macOS Sonoma prior to 14.8.8, and macOS Tahoe prior to 26.6.
Affected products
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Sonoma Before 14.8.8
- Apple macOS Tahoe Before 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: patched