• Sources: primary, discussion
  • Summary: Requesting a no-senders notification on a port and then destroying that port made the kernel take the same port lock twice, so ipc_port_destroy never ran and the waitq lock timed out into a panic. The author reports it is reachable by any local unprivileged process in about twenty lines of C. Apple classified it as non-security because it discloses no data and grants no privilege, assigned no CVE, and credited the fix in the macOS 27, iOS and iPadOS 27, watchOS 27 and visionOS 27 release notes on 2026-09-14.
  • Why it matters: A local denial of service that costs twenty lines and needs no privilege is reachable from any sandboxed app process, and the release notes are the only place the fix is visible.

send feedback on this story