Description
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted file may lead to unexpected app termination.
Published: 2026-08-21
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from insufficient checks when macOS processes a specially crafted file, which can cause the associated application to terminate unexpectedly and result in a denial‑of‑service condition for that application. The weakness is an input validation flaw, aligning with CWE‑20, as the system fails to validate the file contents before processing.

Affected Systems

Apple’s macOS operating system is affected. Vulnerable versions include any macOS releases prior to macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4. After those updates the issue is resolved.

Risk and Exploitability

Without an official CVSS score the severity is not quantified, but the impact is limited to the application that opens the crafted file. The likely attack vector is local; a user with the ability to place or open the file can trigger the crash. No publicly disclosed exploits exist, and the vulnerability is not listed in the CISA KEV catalog. It is vulnerable to local exploitation but does not appear to be remotely exploitable at present.

Generated by OpenCVE AI on August 21, 2026 at 03:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install macOS updates to Sequoia 15.7.5, Sonoma 14.8.5, or Tahoe 26.4 to apply improved checks.
  • Avoid opening unknown or untrusted files until the system has been updated.
  • Review file integrity and use Gatekeeper or antivirus to ensure files are safe before opening.

Generated by OpenCVE AI on August 21, 2026 at 03:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Unexpected Application Termination on macOS Due to Malicious File Processing
Weaknesses CWE-20

Fri, 21 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Fri, 21 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted file may lead to unexpected app termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-21T00:38:59.996Z

Reserved: 2025-11-11T14:43:07.872Z

Link: CVE-2026-20679

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T01:16:59.830

Modified: 2026-08-21T01:16:59.830

Link: CVE-2026-20679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T04:00:13Z

Weaknesses
  • CWE-20

    Improper Input Validation