Impact
An integer overflow in the macOS NFS client can be triggered when a user mounts a share from a malicious NFS server. The overflow occurs because the client does not perform adequate input validation, which leads to corruption of kernel memory or an unexpected system termination. If the corruption reaches critical kernel structures, an attacker could gain elevated privileges or execute arbitrary code at the kernel level.
Affected Systems
Apple macOS versions released before macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are vulnerable. The vulnerability is fixed in these and newer releases.
Risk and Exploitability
Exploitation requires an attacker to host a malicious NFS server that the target system mounts; the attack vector is therefore network-based but local to the victim. The EPSS score of 0.00431 indicates a very low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog, suggesting no confirmed public exploitation. Nonetheless, because the flaw can corrupt kernel memory, it is if discovered and exploited.
OpenCVE Enrichment