Impact
An attacker controlling a malicious NFS server can cause a buffer overflow in the Apple NFS client, leading to kernel memory corruption. The overflow arises from insufficient bounds checking, meaning that data received from the server can overwrite critical memory structures. If exploited, the corrupted memory could allow execution of arbitrary code with kernel privileges, effectively compromising the entire system.
Affected Systems
The flaw affects Apple iOS, iPadOS, macOS, tvOS, and watchOS versions prior to 26.6. All operating systems before the 26.6 release are susceptible because the patch that introduced proper bounds checking was not present.
Risk and Exploitability
The CVSS score is 8.8 and the EPSS score is < 1%, indicating a high severity but a very low probability of exploitation. The potential to corrupt kernel memory and obtain code execution indicates a high threat level. The vulnerability can be triggered remotely by an attacker who can persuade or trick a device into mounting or accessing an NFS share from a malicious server, pointing to an external network attack vector. No mitigations are listed in CISA’s KEV catalog, underscoring the need for timely remediation.
OpenCVE Enrichment