Impact
A use‑after‑free vulnerability in macOS SMB share handling can cause the operating system to crash when a maliciously crafted network share is mounted. The flaw arises from improper memory management, allowing an attacker to trigger a fault that terminates the kernel and brings the entire system to a halt. The impact is loss of availability and potential exposure of crash information.
Affected Systems
Apple macOS is affected. Versions prior to macOS Sequoia 15.8, macOS Tahoe 26.7, and macOS Golden Gate 27 contain the flaw. These macOS release lines require remediation.
Risk and Exploitability
The vulnerability is a classical use‑after‑free (CWE‑416) with a CVSS score of 6.5. The likely attack vector is mounting a maliciously crafted SMB share, which is inferred from the description; an attacker with network access could trigger the flaw. The EPSS score indicates a very low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. The primary risk is denial of service by bringing the system to a halt, with no direct confidentiality or integrity impact.
OpenCVE Enrichment