Description
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a malicious SMB server may lead to unexpected system termination.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper memory handling in macOS occurs when a device connects to an SMB server. A malicious SMB server can trigger a crash, leading to unexpected system termination. The result is a denial‑of‑service condition; no code execution or data exfiltration is possible based on the description.

Affected Systems

Apple macOS versions before Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6 are vulnerable. All vendors refer to these releases by the macOS product name.

Risk and Exploitability

The CVSS score of 9.8 classifies this flaw as critical, while the EPSS score of less than 1% indicates a very low likelihood of exploitation at the moment. The vulnerability is not listed in the CISA KEV catalog. The flaw appears to be exploitable via remote SMB communication; a malicious SMB server can trigger an improper memory handling condition in macOS that causes the system to terminate unexpectedly, resulting in denial of service. No evidence suggests additional impacts such as code execution or data exfiltration.

Generated by OpenCVE AI on August 4, 2026 at 23:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update macOS to the latest release – Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6 – using Apple Software Update.
  • Enable automatic system updates or manually download the Apple Security Update from the official website.
  • Limit SMB access to trusted hosts or temporarily disable SMB if not required for business operations.

Generated by OpenCVE AI on August 4, 2026 at 23:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title macOS SMB Server Crash Leading to Denial of Service

Tue, 04 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title macOS SMB Server Crash Leading to Denial of Service
Weaknesses CWE-122

Sun, 02 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Malicious SMB Server Can Crash macOS via Improper Memory Handling

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Malicious SMB Server Can Crash macOS via Improper Memory Handling
Weaknesses CWE-119
CWE-122
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a malicious SMB server may lead to unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T15:22:19.388Z

Reserved: 2026-04-07T19:58:20.173Z

Link: CVE-2026-39873

cve-icon Vulnrichment

Updated: 2026-07-28T15:21:28.438Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:16:51.340

Modified: 2026-07-28T19:53:04.620

Link: CVE-2026-39873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T00:00:03Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer