Junglewise Threat Intelligence

CVE-2026-84581: Apple macOS buffer overflow in disk image handling

CVE-2026-84581 · Severity: high · CVSS 8.4 · Published 2026-09-14

Technologies: Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

macOS is Apple's operating system for Mac computers. A buffer overflow vulnerability in the disk image mounting code can allow an attacker to cause unexpected system crashes or corrupt kernel memory when a user attempts to mount a maliciously crafted disk image. This could lead to system instability, data loss, or potential privilege escalation.

Technical details

This is a buffer overflow vulnerability (CWE-120) in macOS's disk image handling routines, specifically triggered during the mounting of crafted disk images. The vulnerability stems from insufficient bounds checking when processing disk image metadata or content. The attack vector is local—a user must mount a malicious disk image—but requires no special privileges or authentication. A successful exploit can result in unexpected process termination (denial of service) or corruption of kernel memory, potentially enabling further exploitation. The fix is available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7

References

Related threats