Description
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB share may disclose kernel memory.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Update macOS
AI Analysis

Impact

An out‑of‑bounds read was reported in macOS, mitigated by improved bounds checking. The flaw allows an attacker controlling a malicious SMB share to read kernel memory, potentially exposing sensitive data such as cryptographic keys or passwords. The weakness is a classic information‑disclosure vulnerability, classified under CWE‑200.

Affected Systems

The vulnerability affects Apple macOS systems. The fix is incorporated in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Systems running any earlier build are vulnerable unless they apply the patch.

Risk and Exploitability

Given the lack of published exploitation metrics, the risk remains theoretical but significant. The likely attack vector is a remote SMB session initiated by a user connecting to an attacker‑controlled share. The vulnerability allows kernel memory disclosure, which could enable data theft or privilege escalation. The absence from the CISA KEV catalog does not negate the necessity of patching, especially since the flaw is present in several macOS releases.

Generated by OpenCVE AI on September 15, 2026 at 11:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the macOS update that includes the fix (Golden Gate 27 or later, Sequoia 15.8 or later, Tahoe 26.7 or later).
  • Restrict SMB connections to trusted networks and disable SMB services if not required, reducing exposure.
  • Disable SMBv1 or other older SMB protocols if they are enabled, to reduce the attack surface.

Generated by OpenCVE AI on September 15, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Out of Bounds Read in SMB Causing Kernel Memory Disclosure
Weaknesses CWE-200

Tue, 15 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB share may disclose kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:47:21.073Z

Reserved: 2026-07-22T00:46:06.182Z

Link: CVE-2026-65365

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:21.500

Modified: 2026-09-14T21:17:21.500

Link: CVE-2026-65365

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T11:30:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor