Description
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption that can cause system termination
Action: Patch Immediately
AI Analysis

Impact

An out-of-bounds access was discovered in the macOS SMB client. The flaw arises when a malicious SMB server sends specially crafted data that bypasses bounds checking, causing the kernel to copy data The resulting corruption can lead to unexpected system termination, instability, or other erratic behavior. Although arbitrary code execution was not explicitly described, the kernel memory corruption itself represents a serious reliability and security risk.

Affected Systems

Apple macOS versions before macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are vulnerable. The fix is incorporated in those releases and later ones, so any system running an earlier build is at risk.

Risk and Exploitability

The vulnerability is remote, requiring a connection to a malicious SMB server, making it network‑based and operable without local user interaction. The CVSS score of 7.5 indicates high severity due to kernel memory corruption. The EPSS score of less than 1% reflects a low prevalence of exploitation, and the flaw is not listed in CISA’s KEV catalog. Nevertheless, because the SMB client executes in kernel context, any successful abuse could abruptly terminate processes or destabilize the system. Standard mitigations can reduce exposure until a patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 18:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade macOS to version 27, 15.8, 26.7 or later, which includes the improved bounds‑checking fix for the SMB client.
  • Disable SMB services on the Mac or block SMB traffic through the for the flaw.
  • Monitor network traffic for unexpected SMB connections and investigate any unknown or suspicious SMB activity.

Generated by OpenCVE AI on September 20, 2026 at 18:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Access in macOS SMB Client Leading to Kernel Memory Corruption

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Access in macOS SMB Client Leading to Kernel Memory Corruption

Wed, 16 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 16 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Access in macOS SMB Client Leading to Kernel Corruption
Weaknesses CWE-119

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Access in macOS SMB Client Leading to Kernel Corruption
Weaknesses CWE-119

Tue, 15 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T18:13:49.090Z

Reserved: 2026-09-01T21:13:17.751Z

Link: CVE-2026-84543

cve-icon Vulnrichment

Updated: 2026-09-15T18:13:45.478Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:30.620

Modified: 2026-09-16T14:47:51.130

Link: CVE-2026-84543

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:00:04Z

Weaknesses