Executive brief
An out-of-bounds memory read vulnerability in macOS allows processing of maliciously crafted files to cause unexpected application crashes or leak sensitive data from process memory. This could enable attackers to extract confidential information or disrupt service availability on affected Mac systems.
Technical details
This vulnerability is an out-of-bounds read issue in memory handling, addressed through improved bounds checking. The flaw allows an attacker to process a specially crafted file that triggers reading beyond allocated memory boundaries. Attack preconditions require the user to open or interact with a malicious file; no network access or authentication is required. A successful exploit can result in unexpected process termination (denial of service) or disclosure of sensitive process memory contents. Patches are available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched