Description
An integer underflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to unexpected system termination.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unexpected System Termination (Denial of Service)
Action: Apply Update
AI Analysis

Impact

An integer underflow flaw in Apple’s macOS SMB client causes the system to terminate unexpectedly when it processes crafted SMB‑of‑service condition for the affected machine.

Affected Systems

macOS releases prior to Golden Gate 27, Sequoia 15.8, and Tahoe 26.7 are vulnerable. Updating to these versions or newer resolves the issue.

Risk and Exploitability

The CVSS score is 6.5 and the EPSS score is below 1 %, indicating a low but non listed in the CISA KEV catalog. The likely attack vector is via the SMB protocol when a client initiates communication with a malicious server. The CVE description does not explicitly state authentication requirements, but it is inferred that no client authentication is required, meaning any SMB client could be targeted.

Generated by OpenCVE AI on September 20, 2026 at 20:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update macOS to the latest available version (Golden Gate 27, Sequoia 15.8, Tahoe 26.7 or newer) to apply the fix.
  • If client or block inbound and outbound SMB traffic using the system firewall.
  • Monitor network traffic for anomalous SMB packets and consider rate limiting or packet filtering to reduce exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title SMB Client Integer Underflow Leading to System Crashes

Wed, 16 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 16 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title SMB Client Integer Underflow Leading to System Crashes

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Tue, 15 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An integer underflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T16:43:31.538Z

Reserved: 2026-09-01T21:13:17.750Z

Link: CVE-2026-84536

cve-icon Vulnrichment

Updated: 2026-09-15T16:43:19.988Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:30.057

Modified: 2026-09-16T18:02:20.767

Link: CVE-2026-84536

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:00:05Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound