Impact
An out-of-bounds read occurs when the macOS SMB client processes data received from a malicious SMB server, which can trigger an unexpected system shutdown. The flaw is a memory safety error that enables a remote attacker to read memory beyond the intended bounds, potentially causing a crash and disrupting user operations.
Affected Systems
Apple macOS is affected. The vulnerability is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Vulnerable releases can crash when they connect to a malformed SMB server.
Risk and Exploitability
The flaw is exploitable remotely via a malicious SMB server connection, requiring network access to the target. While the EPSS score is less than 1% and it is not listed in KEV, the nature of the vulnerability suggests that attackers could use it to cause service disruption on any exposed SMB interface. No proof‑of‑concept was reported, but the lack of a prepared mitigation makes the risk significant for environments that maintain SMB access.
OpenCVE Enrichment