Impact
An out-of-bounds access was discovered in the macOS SMB client. The flaw arises when a malicious SMB server sends specially crafted data that bypasses bounds checking, causing the kernel to copy data The resulting corruption can lead to unexpected system termination, instability, or other erratic behavior. Although arbitrary code execution was not explicitly described, the kernel memory corruption itself represents a serious reliability and security risk.
Affected Systems
Apple macOS versions before macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are vulnerable. The fix is incorporated in those releases and later ones, so any system running an earlier build is at risk.
Risk and Exploitability
The vulnerability is remote, requiring a connection to a malicious SMB server, making it network‑based and operable without local user interaction. The CVSS score of 7.5 indicates high severity due to kernel memory corruption. The EPSS score of less than 1% reflects a low prevalence of exploitation, and the flaw is not listed in CISA’s KEV catalog. Nevertheless, because the SMB client executes in kernel context, any successful abuse could abruptly terminate processes or destabilize the system. Standard mitigations can reduce exposure until a patch is applied.
OpenCVE Enrichment