
CVE-2026-84581
Apple macOS
•
severity
published
A bounds-checking flaw in macOS's HFS+ B-tree code allows a malicious disk image to drive a write past a fixed stack traversal buffer while the image is being mounted. The resulting kernel stack corruption can cause unexpected system termination and may corrupt kernel memory.
The HFS+ B-tree header validator accepts a treeDepth of 16, while the affected traversal path stores eight-byte path entries in a 128-byte stack buffer with valid indices from 0 through 15. A traversal at depth 16 therefore writes one entry at path + 0x80, immediately beyond the buffer. Mounting a crafted HFS+ image reaches the vulnerable catalog lookup path and can trigger the kernel's stack-corruption protection.
Apple addressed the issue with improved bounds checking in macOS Sequoia 15.8, macOS Tahoe 26.7, and macOS Golden Gate 27.
References
Explore our other findings
