Impact
An integer underflow flaw in Apple’s macOS SMB client causes the system to terminate unexpectedly when it processes crafted SMB‑of‑service condition for the affected machine.
Affected Systems
macOS releases prior to Golden Gate 27, Sequoia 15.8, and Tahoe 26.7 are vulnerable. Updating to these versions or newer resolves the issue.
Risk and Exploitability
The CVSS score is 6.5 and the EPSS score is below 1 %, indicating a low but non listed in the CISA KEV catalog. The likely attack vector is via the SMB protocol when a client initiates communication with a malicious server. The CVE description does not explicitly state authentication requirements, but it is inferred that no client authentication is required, meaning any SMB client could be targeted.
OpenCVE Enrichment