Junglewise Threat Intelligence

CVE-2026-86901: Apple macOS exFAT out-of-bounds write in file system parsing

CVE-2026-86901 · Severity: high · CVSS 7.1 · Published 2026-09-14

Technologies: Apple macOS, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

macOS includes support for reading and writing exFAT formatted storage devices, commonly used on external drives and USB flash drives. A flaw in how macOS validates memory boundaries when mounting a maliciously crafted exFAT volume could allow an attacker to corrupt kernel memory or crash the system, potentially leading to data loss or enabling further system compromise.

Technical details

An out-of-bounds write vulnerability exists in the exFAT file system driver of macOS Golden Gate. The vulnerability occurs when a user mounts a maliciously crafted exFAT volume; insufficient bounds checking in the file system parsing code allows an attacker to write beyond allocated kernel memory buffers. The attack requires user interaction (mounting a physical storage device) but no special privileges. Successful exploitation can result in kernel memory disclosure or unexpected system termination (denial of service). The vulnerability is fixed in macOS Golden Gate 27 through improved bounds checking in the file system driver.

Affected products

  • Apple macOS Golden Gate before 27

Timeline

  • 2026-09-14: patched: Fixed in macOS Golden Gate 27

References

Related threats