Impact
An out‑of‑bounds read was reported in macOS, mitigated by improved bounds checking. The flaw allows an attacker controlling a malicious SMB share to read kernel memory, potentially exposing sensitive data such as cryptographic keys or passwords. The weakness is a classic information‑disclosure vulnerability, classified under CWE‑200.
Affected Systems
The vulnerability affects Apple macOS systems. The fix is incorporated in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Systems running any earlier build are vulnerable unless they apply the patch.
Risk and Exploitability
Given the lack of published exploitation metrics, the risk remains theoretical but significant. The likely attack vector is a remote SMB session initiated by a user connecting to an attacker‑controlled share. The vulnerability allows kernel memory disclosure, which could enable data theft or privilege escalation. The absence from the CISA KEV catalog does not negate the necessity of patching, especially since the flaw is present in several macOS releases.
OpenCVE Enrichment