CVE-2026-84581
massKernel Buffer Overflow via Malicious Disk Images in macOS
CVE-2026-84581 is a buffer overflow (CWE-120) in macOS's handling of disk images, fixed by Apple with improved bounds checking. The flaw is triggered when the system mounts a maliciously crafted disk image, which may cause unexpected system termination or corruption of kernel memory — implying at minimum a denial of service and potentially kernel-level code execution. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:N, base 8.4) indicates a local attacker needs no privileges and no user interaction beyond the mount occurring, so any scenario where a crafted image is mounted (e.g., an auto-mounted or socially delivered .dmg) is sufficient. All Macs running macOS releases earlier than the fixed versions are affected. No public proof of concept is known and the issue is not on the CISA KEV list, so exploitation in the wild appears unlikely at this time.
What to do: Update to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 or later as soon as possible. Do not mount disk images (.dmg/.iso/.sparseimage) from untrusted sources, and disable browser options that automatically open or mount downloaded files. Administrators should audit fleet patch levels and consider restricting disk-image mounting (e.g., via MDM policy or hdiutil restrictions) for high-risk users.
| Apple macOS Sequoia | prior to 15.8 (fixed in 15.8) |
| Apple macOS Tahoe | prior to 26.7 (fixed in 26.7) |
| Apple macOS Golden Gate | prior to 27 (fixed in 27, per vendor advisory) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory.
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.