Apple macOS

•

severity

8.4

published

A bounds-checking flaw in macOS's HFS+ B-tree code allows a malicious disk image to drive a write past a fixed stack traversal buffer while the image is being mounted. The resulting kernel stack corruption can cause unexpected system termination and may corrupt kernel memory.

The HFS+ B-tree header validator accepts a treeDepth of 16, while the affected traversal path stores eight-byte path entries in a 128-byte stack buffer with valid indices from 0 through 15. A traversal at depth 16 therefore writes one entry at path + 0x80, immediately beyond the buffer. Mounting a crafted HFS+ image reaches the vulnerable catalog lookup path and can trigger the kernel's stack-corruption protection.

Apple addressed the issue with improved bounds checking in macOS Sequoia 15.8, macOS Tahoe 26.7, and macOS Golden Gate 27.

References

CVSS v3.1

8.4

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1

8.4

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1

8.4

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

S1t3aMr8tL  lZoSo$k&iWn8gU  a8t7  y&oKuVr1  sFo$f5t2wJaZr4eW  cOrVi8tUi8cNa8l&lZyH.S

request briefing

request briefing

SPt5aKr@tE  lUo8o9kEiKnXg4  a4tN  y2o0uHr&  sLoEfRtOwYaBr8eN  c8rKi0tVi7cDaOlOl2y6.&

request briefing

request briefing

SHtZaCr4t&  l1oNo6k2i%n#gO  a9t1  yPoGuLrF  sUoWf0tIw1aBr1e2  cArYiGt4iDc5a%l#lVyM.K

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026