Researchers at Photon reported a bug in Apple’s XNU kernel that can cause macOS 26 systems with long continuous uptime to stop accepting new TCP/IP connections after roughly 49 days, 17 hours, 2 minutes, and 47 seconds. The flaw stems from an overflow in the 32-bit unsigned tcp_now counter used by the TCP stack; once it wraps, the internal TCP timestamp clock stops behaving correctly, TIME_WAIT connections are no longer cleaned up, ephemeral ports accumulate, and the system gradually loses the ability to establish new TCP sessions. Existing connections may continue to function, and ICMP traffic such as ping can still succeed, making the failure less obvious at first.
Photon said it reproduced the issue on machines used to monitor iMessage services and traced the root cause to a comparison in the kernel’s TCP handling that appears inconsistent with behavior described in RFC 7323. Reports indicate the bug affects macOS 26 rather than earlier releases, and that most consumer users are unlikely to encounter it because routine updates and reboots usually occur before the uptime threshold is reached. For long-running Macs, especially server-like systems that rarely reboot or sleep, the current workaround is simply to restart the machine until Apple releases a fix.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A subsequent analysis highlighted that the bug appears to affect macOS 26 rather than earlier versions and is unlikely to impact most consumer users because their Macs are typically rebooted before reaching the uptime threshold. It advised operators of long-running Macs and servers to monitor systems or restart them proactively until Apple releases a fix.
Photon publicly disclosed that long-running macOS 26 systems can gradually lose the ability to establish new TCP/IP connections due to the kernel timestamp overflow bug. The report noted that rebooting restores functionality and suggested the issue may relate to Apple's implementation of behavior described in RFC 7323.
Researchers at Photon identified a macOS XNU kernel bug on systems used to monitor iMessage services, reproduced it on two machines, and traced it to a 32-bit tcp_now counter overflow that occurs after 49 days, 17 hours, 2 minutes, and 47 seconds of uptime. The flaw causes TIME_WAIT connections to stop expiring, ephemeral ports to be exhausted, and new TCP connections to eventually fail while some existing connectivity may continue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
tidbits.com
Open sourcetomshardware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.