TL;DR
Security researcher Peter Malone has published a full technical analysis and proof-of-concept code for CVE-2026-43682, a macOS HFS+ vulnerability rated CVSS 9.8. A malformed disk image can make the kernel copy 2,886 bytes into a 522-byte buffer. Apple fixed the bug on July 27, 2026, so unpatched Macs now face a publicly documented attack path.
- CVE: CVE-2026-43682
- CVSS: 9.8 (Critical · CVSSv3)
- Product: Apple macOS
- Affected: < 14.8.8, < 15.7.8, < 26.6
- Impact: CWE-119
- Status: No confirmed exploitation yet
- Patched in: 14.8.8, 15.7.8, 26.6
- EPSS: 0.7% (30-day)
- Action: Update to 14.8.8, 15.7.8, 26.6 now
Tired of noisy Apple CVE feeds? Set your own EPSS/CVSS alert threshold.
Try free for 14 daysWhy It Matters
The bug details and working PoC are now public on the researcher’s CVE-2026-43682 GitHub repository. As a result, anyone can now study how to trigger this macOS HFS+ vulnerability and crash an unpatched Mac. Apple’s advisory warns that “a remote user may be able to cause unexpected system termination or corrupt kernel memory.”
Malone reported the bug on March 8, 2026. Apple awarded him a $20,000 bounty just 46 days later. Patches followed on July 27.
Malone stresses one limit. In his words, “The PoC is a disk-image generator, not a privilege-escalation exploit.” So far, no exploitation in the wild has been confirmed. Apple also credited five other researchers for reporting the same flaw.
How the Attack Works
CVE-2026-43682 is a kernel heap overflow in the HFS+ file system driver. HFS+ stores extended attributes in a B-tree. When the kernel walks that tree, it copies each key into a fixed buffer. However, the code reads the key length straight from the disk and never checks it against the tree’s maximum.
Malone set one key length to 2,884 bytes. The key still fit inside an 8 KiB node, so it passed the existing checks. As he puts it, “The on-disk record was large enough. The in-memory object was not.” Simply listing the files’ extended attributes then triggered a kernel panic.
Notably, the overflow is deterministic. Whether it crashes right away depends on where the kernel’s memory guards land.
Affected Versions
Malone reproduced the macOS HFS+ vulnerability on Apple silicon running macOS Tahoe 26.3. Apple’s fix covers three releases. Any Mac below these versions is exposed:
- macOS Tahoe 26.6
- macOS Sequoia 15.7.8
- macOS Sonoma 14.8.8
Patch and Mitigation Steps
Update macOS through System Settings now. Apple describes the fix as “improved memory handling” in three security notes: Apple advisory 128067, Apple advisory 128071, and Apple advisory 128072.
Until every Mac is patched, avoid mounting disk images from unknown sources. Malone notes that attaching or indexing an image “may be enough to reach the vulnerable attributes path.”
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!