CVE-2026-43682
macOS HFS kernel memory corruption
Apple fixed CVE-2026-43682 in the HFS component of macOS Tahoe 26.6, Sequoia 15.7.8, and Sonoma 14.8.8 on 27 July 2026. Apple says a remote user may cause unexpected system termination or corrupt kernel memory. CISA ADP scores it CVSS 3.1 9.8. A public crash-oriented PoC exists. Not in CISA KEV.
- CVSS
- 9.8
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Class
- Other
- Status
- PoC Available
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Apple
- Products
- macOS Tahoe, macOS Sequoia, macOS Sonoma, HFS
- Affected
- macOS Tahoe before 26.6, macOS Sequoia before 15.7.8, and macOS Sonoma before 14.8.8, per Apple and the CVE record.
- Fixed
- macOS Tahoe 26.6, macOS Sequoia 15.7.8, and macOS Sonoma 14.8.8.
- CWE
- CWE-119
- Published
- 27 Jul 2026
- Updated
- 5 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2026-43682 is listed under the HFS component in Apple’s security notes for macOS Tahoe 26.6, macOS Sequoia 15.7.8, and macOS Sonoma 14.8.8, all released 27 July 2026. Apple’s Impact line is that a remote user may be able to cause unexpected system termination or corrupt kernel memory. The Description is that the issue was addressed with improved memory handling. Apple credits Trung Nguyen (@everping) of CyStack, Peter Malone, Nicolas Rabrenovic, Dave G., and Atul R V & Ashmit Sharma.
Apple did not publish a CVSS score. NVD records a CVSS 3.1 base score of 9.8 with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H from CISA ADP (Secondary), and NVD’s Secondary weakness is CWE-119. NVD vulnStatus is Analyzed. CISA’s SSVC options for this CVE set exploitation to none. The CVE is not in the CISA KEV catalog.
A public repository at github.com/petermalone/CVE-2026-43682 describes a crash-oriented proof of concept for an HFS+ attributes B-tree key length that leads to an oversized kernel heap copy when a crafted disk image is mounted and extended attributes are listed. The GitHub account petermalone matches a name Apple credits for this CVE. The repository contains Python and C sources, a shell helper, and sanitized panic notes; ThreatWire did not find packaged binaries in the tree and did not reproduce the project. The README claims a kernel panic / out-of-bounds write path, not demonstrated remote code execution. This record does not reprint payloads or commands.