Impact
An out‑of‑bounds read has been identified in the macOS NFS client. If a user’s system connects to a malicious NFS server, the client can read beyond the bounds of a buffer, leading to kernel memory corruption. The corrupted kernel memory can cause unexpected system termination, effectively denying service to the affected machine.
Affected Systems
Vulnerable macOS releases are those that precede the fixed versions. Specifically, macOS versions prior to Golden Gate 27, Sequoia 15.8, and Tahoe 26.7 are affected. The flaw resides in Apple’s macOS NFS client component and can impact any system that connects to an NFS server.
Risk and Exploitability
The vulnerability can be exploited remotely by any entity that can host a rogue NFS server that a macOS machine will connect to. Given a CVSS score of 7.5, the flaw is classified as high severity, while the EPSS score of < 1% indicates a low probability of exploitation. Despite the lack of a KEV listing, the risk remains significant in environments that rely on NFS. Successful exploitation could crash the system, so the risk is considered severe.
OpenCVE Enrichment