Skip to content
THREATWIRE

News

macOS HFS kernel bug is CVE-2026-43682

Apple patched CVE-2026-43682 in the HFS component on 27 July 2026 in macOS Tahoe 26.6, Sequoia 15.7.8, and Sonoma 14.8.8. Apple warns of unexpected system termination or kernel memory corruption. CISA ADP scores it 9.8. A public crash PoC exists. Not in CISA KEV.

Critical

Published 5 Oct 2026

PoC link

On this page

What happened

On 27 July 2026 Apple released macOS Tahoe 26.6, macOS Sequoia 15.7.8, and macOS Sonoma 14.8.8. Each security note lists CVE-2026-43682 under the HFS component. Apple’s Impact text says a remote user may be able to cause unexpected system termination or corrupt kernel memory. The Description is that the issue was addressed with improved memory handling. The credited researchers include Trung Nguyen (@everping) of CyStack, Peter Malone, Nicolas Rabrenovic, Dave G., and Atul R V & Ashmit Sharma.

NVD published the record the same day. It carries a CVSS 3.1 score of 9.8 with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That score comes from CISA ADP as a Secondary metric, not from Apple. NVD also records CWE-119 from the same Secondary source and marks the entry Analyzed.

Who is affected

Apple’s fixed versions are macOS Tahoe 26.6, macOS Sequoia 15.7.8, and macOS Sonoma 14.8.8. The CVE record lists those products as affected before those builds. Any Mac still below those versions on the Tahoe, Sequoia, or Sonoma lines remains in the vendor’s named range. The component is HFS, so systems that never process HFS+ content through the vulnerable path are outside the practical trigger the public analysis describes, but Apple’s advisory does not carve out that exemption in the Impact line.

What is confirmed

Apple’s three security pages agree on component, Impact, Description, and the fixed releases. CISA has not added CVE-2026-43682 to the Known Exploited Vulnerabilities catalog, and CISA’s SSVC options for the CVE set exploitation to none. GitHub Security Advisory GHSA-wmj5-pr45-6gg2 mirrors the NVD/CISA ADP score and vector.

A public repository owned by GitHub user petermalone is titled as an HFS+ B-tree kernel heap overflow PoC for this CVE. Apple’s credit line for CVE-2026-43682 includes Peter Malone. The repository README and sanitized panic notes describe mounting a crafted HFS+ disk image and listing extended attributes to reach an oversized kernel heap copy that panics under PGZ. The claimed result is a crash / out-of-bounds write path, not demonstrated code execution. The tree is small source files (Python, C, shell) plus documentation; ThreatWire did not find shipped binaries there and did not reproduce the project. Availability is therefore PoC.

What is not confirmed

Apple’s Impact wording uses “remote user.” That is Apple’s language, and CISA ADP used attack vector Network with no user interaction in the 9.8 score. Apple does not publish its own CVSS for this CVE. The same HFS section of the Apple notes also contains neighboring CVEs whose Impact lines say “Mounting a maliciously crafted disk image,” and the public PoC for CVE-2026-43682 is built around a crafted disk image being attached and extended attributes being listed. ThreatWire therefore does not treat the social headline “remote” as proof of an unauthenticated network kernel exploit with no local attachment or content-processing step.

The public repository’s GitHub profile is sparse (no name, bio, or company on the account page). That is a mild trust caution for macOS PoC repos in general, but it is outweighed here by Apple’s matching credit name and the absence of packaged binaries in the tree. Exploitation in the wild is not confirmed by Apple or CISA. The PoC does not establish remote code execution.

What to do

Update to macOS Tahoe 26.6, macOS Sequoia 15.7.8, or macOS Sonoma 14.8.8, depending on the installed major release. Until that update is installed, avoid mounting or attaching untrusted HFS+ disk images and untrusted disk-image downloads that could be processed as HFS+. After updating, confirm the installed build in System Settings.

Sources: Apple security content for macOS Tahoe 26.6, Sequoia 15.7.8, and Sonoma 14.8.8; NVD; CVE.org; GHSA-wmj5-pr45-6gg2; and the petermalone public PoC repository.

Related CVEs

Sources

Share on X@threatwire_https://www.threatwire.tech/news/macos-hfs-kernel-bug-is-cve-2026-43682

More articles