Public PoC lands for macOS HFS+ kernel overflow triggered by a malicious disk image
A working exploit generator and full write-up are now public for CVE-2026-43682, a kernel heap overflow Apple fixed in July. Mounting a crafted disk image is enough to corrupt kernel memory.
At a glance
- CVE-2026-43682 is a kernel heap overflow in the macOS HFS+ driver; Apple says it can cause unexpected system termination or corrupt kernel memory.
- Researcher Peter Malone published the technical analysis and a working proof-of-concept on October 5, about ten weeks after the fix shipped.
- The bug is reached by mounting a crafted disk image and listing extended attributes; no exploitation in the wild has been confirmed.
- Apple patched it on July 27 in macOS Tahoe 26.6, Sequoia 15.7.8 and Sonoma 14.8.8.
A working proof-of-concept and a full technical write-up are now public for CVE-2026-43682, a kernel heap overflow in the HFS+ file system driver that Apple patched in macOS in July. Researcher Peter Malone published the details on October 5, roughly ten weeks after the fix shipped, turning a quietly patched memory-corruption bug into something any Mac still running an older build should treat as pressing.
What happened
Apple's advisory for macOS Tahoe 26.6, released on July 27, 2026, lists the issue under the "HFS" component and describes the impact as "a remote user may be able to cause unexpected system termination or corrupt kernel memory." Apple said "a buffer overflow was addressed with improved bounds checking," and credited the report to Trung Nguyen (@everping) of CyStack, Dave G., Nicolas Rabrenovic, Atul R V and Ashmit Sharma, and Peter Malone — an unusually long credit list, which indicates several researchers found the same defect independently.
According to SecurityOnline, which reported the publication, public vulnerability databases score the flaw 9.8. Apple does not assign CVSS ratings in its own advisories, so that figure comes from third parties rather than the vendor. SecurityOnline also noted that no exploitation in the wild has been confirmed.
Technical details
Malone's write-up places the bug in the way HFS+ walks the attributes B-tree, the structure that stores extended attributes. Per the repository, the code copies a record's key into a fixed BTreeKey structure with room for 522 bytes without first checking the key length against that buffer. A crafted disk image can declare an oversized key — the write-up describes one of roughly 2,900 bytes — that passes the initial validation and then overflows the destination during the memmove, corrupting the kernel heap. The missing check affected several B-tree routines, including BTSearchRecord, BTIterateRecord and BTIterateRecords.
The published proof-of-concept is a generator that builds such a malformed image. According to the repository, mounting the image and then listing extended attributes with ls -l@ is enough to walk into the vulnerable code and panic the kernel. Malone reproduced the crash on macOS Tahoe 26.3 with com.apple.filesystems.hfs.kext version 704.60.4.
Malone's timeline shows the bug was reported to Apple on March 8, 2026, earned a $20,000 bounty on April 23, and was fixed on July 27.
Who is affected
Apple fixed the issue in macOS Tahoe 26.6, macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8, all released on July 27, 2026. Macs on earlier builds of those branches remain exposed. The reach of the bug is wider than HFS+ usage suggests: the driver is still present and loadable on current macOS even though APFS has long been the default file system, so a machine does not need an HFS+ volume of its own to parse an attacker's HFS+ image.
What to do
Update affected Macs to the July builds or later. Until that is done, the practical guidance is to avoid mounting disk images from untrusted sources. With a public proof-of-concept available, a .dmg arriving by email, download or a shared network volume is now a realistic route to a kernel panic at minimum, and a routine extended-attribute listing — or Spotlight indexing a freshly mounted volume — can be enough to reach the vulnerable code. Fleet administrators should also check whether mobile device management policies still allow users to mount arbitrary disk images, since that is the precondition the exploit depends on.
Related CVEs
Sources
- Researcher Publishes Technical Details and PoC Exploit for macOS HFS+ Kernel Flaw CVE-2026-43682 — SecurityOnline
- CVE-2026-43682 — write-up and proof-of-concept — Peter Malone (GitHub)
- About the security content of macOS Tahoe 26.6 — Apple
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



