ZeroHour

CVE-2026-28934

mass

macOS Disk Image Mounting Buffer Overflow Can Crash the System

CVSS 3.1
6.5 medium
EPSS
Published
()
Modified
AI analysis

A buffer overflow in Apple's macOS disk image handling was fixed with improved bounds checking, with patches shipping in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. The flaw is triggered when a user mounts a maliciously crafted disk image, which may cause unexpected system termination. Apple's advisory credits the bug only with a crash/DoS, but memory-corruption flaws of this class warrant prompt patching since code execution cannot be ruled out. All Macs running macOS Sequoia before 15.8, macOS Tahoe before 26.7, or macOS Golden Gate before 27 are affected. No public proof-of-concept or in-the-wild exploitation is known, and the issue is not on CISA's KEV list.

What to do: Update to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 depending on the installed major version. Instruct users not to mount disk images (.dmg, .iso, sparse bundles) from untrusted sources or unexpected downloads. No other workaround is documented, so patching via Software Update is the primary mitigation.

Affected
Apple macOS Sequoiabefore 15.8
Apple macOS Tahoebefore 26.7
Apple macOS Golden Gatebefore 27
Estimated exposure
masstens of millions of Macs (Sequoia and Tahoe are the two most recently shipped macOS releases) — Apple's active Mac installed base exceeds 100 million devices, and the two newest macOS releases typically account for the majority of that base within months of shipping.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a malicious disk image may cause unexpected system termination.

Vendors
apple
Products
macos
Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.