Impact
An out-of-bounds write occurs in the SMB handling code of Apple macOS when processing packets from a SMB server, enabling the attacker to corrupt kernel memory. This flaw is a classic buffer overflow (CWE-787). Kernel corruption can lead to privilege escalation or arbitrary code execution, thereby compromising system integrity.
Affected Systems
Apple macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are affected. All installations of these releases should be checked and updated to a patched build in which bounds checking has been restored.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate to high severity. The EPSS score is less than 1%, suggesting a low likelihood of exploitation in the wild; the vulnerability is not listed in the CISA KEV catalog. The flaw is remote and can be triggered by simply connecting to a malicious SMB server, which may occur via standard SMB traffic or exposed network shares.
OpenCVE Enrichment