Description
A stack overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial-of-service.
Published: 2026-07-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack overflow was reported in macOS caused by insufficient input validation. The vulnerability allows an application that can supply crafted input to corrupt the stack and cause a crash, resulting in a denial of service. The CVE description does not provide details about additional privileges or data disclosure. Based on the wording, the primary impact is loss of availability, and the problem resides in input handling, a classic control‑flow failure.

Affected Systems

The vulnerability affects Apple macOS. The affected releases are macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Users running any earlier or later build without the fix are at potential risk.

Risk and Exploitability

The flaw is a stack overflow that may be triggered by an application supplying malformed input. The CVE does not detail the specific component or operating conditions required. The CVSS score of 7.1 indicates a high severity. The EPSS score is below 1%, and the issue is not listed in CISA’s KEV catalog, indicating no publicly identified exploitation. Because the attack requires that the vulnerable component process crafted input, an attacker would need some form of execution or local influence to trigger the crash. Upgrading to the patched releases is the most reliable mitigation.

Generated by OpenCVE AI on August 13, 2026 at 10:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, or macOS Tahoe 26.6 which contain the stack‑overflow fix.
  • If an immediate upgrade is not possible, block or quarantine any untrusted applications that may provide crafted input to the affected component to reduce the chance of a crash.
  • Implement monitoring of application crashes to detect patterns that may indicate exploitation attempts.

Generated by OpenCVE AI on August 13, 2026 at 10:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Stack Overflow in macOS Causing Denial of Service

Wed, 12 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Stack Overflow Causing Denial of Service in macOS
Weaknesses CWE-20

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Stack Overflow Causing Denial of Service in macOS
Weaknesses CWE-20

Sun, 02 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Stack Overflow Leading to Denial of Service in macOS
Weaknesses CWE-120

Sat, 01 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Stack Overflow Leading to Denial of Service in macOS
Weaknesses CWE-120

Tue, 28 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A stack overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial-of-service.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T13:39:39.433Z

Reserved: 2026-05-01T22:46:27.818Z

Link: CVE-2026-43771

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:01.477

Modified: 2026-07-28T18:07:16.727

Link: CVE-2026-43771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:30:04Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow