Description
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted file may lead to unexpected app termination.
Published: 2026-08-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Application Crash (Denial of Service)
Action: Patch OS
AI Analysis

Impact

The vulnerability is triggered when macOS processes a specially crafted file that lacks proper bounds checks. Processing such a file can cause the targeted application to terminate unexpectedly, leading to a denial‑of‑service condition for the user of that application. The weakness is represented by heap out‑of‑bounds read (CWE‑125) and a potential use‑after‑free (CWE‑416).

Affected Systems

Apple’s macOS may be affected. Vulnerable releases include any macOS prior to Sequoia 15.7.5, Sonoma 14.8.5, and Tahoe 26.4. The issue has been resolved in those newer OS releases.

Risk and Exploitability

With a CVSS score of 4.3 the severity is moderate, but the EPSS score of less than 1 % indicates a very small likelihood of exploitation under normal circumstances. The attack vector appears to be local, requiring a user to place or open a malicious file; no public exploits or remote exploitation pathways are known. The vulnerability is not listed in the CISA KEV catalog, reflecting its limited exploitation scope.

Generated by OpenCVE AI on August 21, 2026 at 23:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install macOS updates to Sequoia 15.7.5, Sonoma 14.8.5, or Tahoe 26.4 to apply the fix.
  • Avoid opening unknown or untrusted files until the system has been updated.
  • Use Gatekeeper or antivirus scanning to ensure files are safe before opening.

Generated by OpenCVE AI on August 21, 2026 at 23:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Fri, 21 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Malicious File Triggers Application Crash in macOS

Fri, 21 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unexpected Application Termination on macOS Due to Malicious File Processing
Weaknesses CWE-20

Fri, 21 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-416
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Unexpected Application Termination on macOS Due to Malicious File Processing
Weaknesses CWE-20

Fri, 21 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Fri, 21 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted file may lead to unexpected app termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-21T19:48:44.209Z

Reserved: 2025-11-11T14:43:07.872Z

Link: CVE-2026-20679

cve-icon Vulnrichment

Updated: 2026-08-21T19:48:13.480Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-21T01:16:59.830

Modified: 2026-08-24T17:11:05.683

Link: CVE-2026-20679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T23:30:17Z

Weaknesses