CVE-2026-43682 is a memory-handling vulnerability in Apple macOS. A remote user may be able to trigger unexpected system termination or corrupt kernel memory. Apple addressed the issue through improved memory handling in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This eight-file repository is an operational local file-based proof of concept for CVE-2026-43682, an HFS+ B-tree key-length validation flaw in macOS. The core generator, poc/craft_attr_poc_asb.py, copies a base DMG, locates its HFS+ volume header and attributes fork, then modifies an attributes-B-tree leaf record so its on-disk key length exceeds the fixed in-memory BTreeKey capacity. A vulnerable HFS+ kernel path calculates the untrusted length plus two and copies up to 2,886 attacker-controlled bytes into a 522-byte iterator key buffer, causing a kernel heap overflow. poc/create_base_dmg.sh creates a 4 MiB HFS+ image and populates extended attributes to ensure an attributes tree exists. poc/check_commpage.c is an optional Apple-silicon helper that displays fixed commpage values. The Python generator directly reads the kernel target value from the commpage and repeats a rotated byte pattern in the oversized key, allowing the overflow data to be correlated with panic registers. README.md and evidence/PANIC.md document reproduction, root cause, and a PGZ-confirmed out-of-bounds write on macOS Tahoe 26.3 with hfs.kext 704.60.4. There are no remote network calls, C2 endpoints, shells, persistence mechanisms, or escalation payloads; the demonstrated capability is local kernel-memory corruption and denial of service when a crafted image is mounted and its extended attributes are accessed.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.