securityonline.info 5 Oct 2026, 00:28 UTC

Public Exploit Targets Critical macOS HFS+ Kernel Flaw

Public Exploit Targets Critical macOS HFS+ Kernel Flaw
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

SECURITY researchers have disclosed technical details and a proof-of-concept exploit for CVE-2026-43682, a critical kernel flaw in macOS HFS+. The bug is a heap overflow in the HFS+ file system driver that occurs when the kernel copies disk-stored keys into a fixed-size in-memory buffer. The PoC uses a malformed disk image to trigger a copy of 2,884 bytes into an 8 KiB node, with the on-disk record being large enough to bypass existing checks.

Apple’s advisory notes that a remote user may cause unexpected system termination or memory corruption, and the PoC is described as a disk-image generator rather than a privilege-escalation exploit. At the time of publication, there were no confirmed reports of active exploitation.

Affected macOS versions are those below macOS Tahoe 26.6, macOS Sequoia 15.7.8, and macOS Sonoma 14.8.8. Apple has patched the vulnerability in 14.8.8, 15.7.8 and 26.6. Users should update immediately through System Settings. Until patches reach all systems, the article advises caution when mounting disk images from unknown sources, since attaching or indexing an image could trigger the vulnerable code path.

The PoC is public, and while Malone emphasises it does not constitute a privilege-escalation exploit, the exposure remains a critical remote threat for unpatched Macs.

View full article

Article by CyberSIXT