Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Mounting a malicious disk image may cause unexpected system termination.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write that occurs while processing disk images. When a malicious image is mounted, the unchecked write can corrupt memory, leading to an unexpected system termination. The primary consequence is loss of availability for the affected machine, as the crash forces the system to reboot or become unresponsive.

Affected Systems

Apple macOS releases prior to Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6 are affected. Users running any earlier version of those macOS code names are vulnerable; the issue is addressed in the listed update releases.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.5, an EPSS score of less than 1%, and is not listed in the CISA KEV catalog, indicating no known widespread exploitation at this time. Attackers could trigger the fault by submitting a crafted disk image, and the likely attack vector is local mounting of the disk image; the CVE does not specify a remote exploitation path. Because the failure results in a crash rather than code execution, the risk is lower than for a vulnerability that provides remote code execution.

Generated by OpenCVE AI on September 20, 2026 at 18:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update macOS to a version that contains the fix – Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6, or any newer release.
  • Avoid mounting disk images from untrusted sources until the system is updated.
  • Keep the system and security updates applied promptly to maintain protection against known and emerging vulnerabilities.

Generated by OpenCVE AI on September 20, 2026 at 18:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bound Write in Disk Image Handling Causes System Crash

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bound Write in Disk Image Handling Causes System Crash

Wed, 16 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Disk Image Mounting Leads to System Termination

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Disk Image Mounting Leads to System Termination
Weaknesses CWE-787

Tue, 15 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Mounting a malicious disk image may cause unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T14:34:17.464Z

Reserved: 2026-05-01T22:46:27.817Z

Link: CVE-2026-43761

cve-icon Vulnrichment

Updated: 2026-09-15T14:34:12.518Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:10.687

Modified: 2026-09-15T19:23:08.817

Link: CVE-2026-43761

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:00:04Z

Weaknesses