Description
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption with potential privilege escalation
Action: Patch
AI Analysis

Impact

An integer overflow in the macOS NFS client can be triggered when a user mounts a share from a malicious NFS server. The overflow occurs because the client does not perform adequate input validation, which leads to corruption of kernel memory or an unexpected system termination. If the corruption reaches critical kernel structures, an attacker could gain elevated privileges or execute arbitrary code at the kernel level.

Affected Systems

Apple macOS versions released before macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are vulnerable. The vulnerability is fixed in these and newer releases.

Risk and Exploitability

Exploitation requires an attacker to host a malicious NFS server that the target system mounts; the attack vector is therefore network-based but local to the victim. The EPSS score of 0.00431 indicates a very low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog, suggesting no confirmed public exploitation. Nonetheless, because the flaw can corrupt kernel memory, it is if discovered and exploited.

Generated by OpenCVE AI on September 20, 2026 at 20:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update macOS to macOS Golden Gate 27, Sequoia 15.8, or Tahoe 26.7 or later to apply the vendor patch
  • Disable the NFS client service or block outbound NFS traffic until the system can be updated
  • Once updated, mount NFS shares only from trusted, verified servers and monitor for anomalous NFS activity

Generated by OpenCVE AI on September 20, 2026 at 20:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in macOS NFS Client Leading to Kernel Memory Corruption

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in macOS NFS Client Leading to Kernel Memory Corruption
Weaknesses CWE-190
CWE-416

Tue, 15 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in macOS NFS Client Leading to Kernel Memory Corruption
Weaknesses CWE-190
CWE-416

Tue, 15 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T20:27:42.908Z

Reserved: 2026-09-01T21:13:17.751Z

Link: CVE-2026-84544

cve-icon Vulnrichment

Updated: 2026-09-17T20:27:29.647Z

cve-icon NVD

Status : Modified

Published: 2026-09-14T21:17:30.727

Modified: 2026-09-17T21:17:48.950

Link: CVE-2026-84544

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:15:04Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound