Executive brief
macOS is Apple's operating system for Mac computers. A buffer overflow vulnerability in the kernel allows a local attacker to crash the system or corrupt kernel memory, potentially enabling complete system compromise. This requires local access but poses a critical risk to system stability and security.
Technical details
A buffer overflow vulnerability exists in kernel memory handling due to insufficient size validation. The vulnerability allows a local attacker to write beyond allocated buffer boundaries, potentially corrupting kernel memory. Attack requires local access to the affected macOS system. Successful exploitation can result in unexpected system termination (kernel panic) or arbitrary kernel memory corruption, which could enable privilege escalation or further system compromise. The vulnerability is addressed in macOS Golden Gate 27 through improved size validation and bounds checking.
Affected products
- Apple macOS Golden Gate prior to 27
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixed in macOS Golden Gate 27