Impact
An out‑of‑bounds read in the macOS kernel's SMB module can allow an attacker to read portions of kernel memory. The flaw is due to insufficient bounds checking and is classified as CWE‑125. The attack does not provide code execution or privilege escalation, but it can expose sensitive kernel information that an attacker might use for further exploitation.
Affected Systems
Apple macOS installations that have not been updated to macOS Golden Gate 27, Sequoia 15.8, or Tahoe 26.7 are vulnerable. The issue resides in the kernel SMB subsystem across all builds prior to these versions. Systems that remain on older releases without the bounds‑checking patch remain at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity; the EPSS score of less than 1 % shows a very low but non‑zero chance of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an attacker hosting a malicious SMB share and a user connecting to it, which can trigger the read of kernel memory and disclose sensitive data. No activation of additional privileges is required for the exploit.
OpenCVE Enrichment