Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to kernel memory corruption.
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption via malicious SMB server
Action: Patch Immediately
AI Analysis

Impact

An out-of-bounds write occurs in the SMB handling code of Apple macOS when processing packets from a SMB server, enabling the attacker to corrupt kernel memory. This flaw is a classic buffer overflow (CWE-787). Kernel corruption can lead to privilege escalation or arbitrary code execution, thereby compromising system integrity.

Affected Systems

Apple macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are affected. All installations of these releases should be checked and updated to a patched build in which bounds checking has been restored.

Risk and Exploitability

The CVSS score of 7.8 indicates moderate to high severity. The EPSS score is less than 1%, suggesting a low likelihood of exploitation in the wild; the vulnerability is not listed in the CISA KEV catalog. The flaw is remote and can be triggered by simply connecting to a malicious SMB server, which may occur via standard SMB traffic or exposed network shares.

Generated by OpenCVE AI on September 20, 2026 at 19:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the macOS update that includes the SMB bounds‑check fix.
  • Configure firewalls or network segmentation to restrict or block incoming SMB traffic from untrusted sources.
  • If SMB sharing is required, limit access to trusted hosts and enable authentication mechanisms; disable SMB services when not needed.

Generated by OpenCVE AI on September 20, 2026 at 19:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in SMB Handler Allows Kernel Corruption on macOS

Wed, 16 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 16 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in SMB Handler Allows Kernel Corruption on macOS

Wed, 16 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Out-Of-Bounds Write in SMB Handling Leads to Kernel Memory Corruption
Weaknesses CWE-120

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Out-Of-Bounds Write in SMB Handling Leads to Kernel Memory Corruption
Weaknesses CWE-120

Tue, 15 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to kernel memory corruption.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T03:56:43.260Z

Reserved: 2026-09-01T21:13:17.748Z

Link: CVE-2026-84515

cve-icon Vulnrichment

Updated: 2026-09-15T18:24:44.031Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:28.043

Modified: 2026-09-16T18:01:09.777

Link: CVE-2026-84515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:15:03Z

Weaknesses