Description
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

An out‑of‑bounds read has been identified in the macOS NFS client. If a user’s system connects to a malicious NFS server, the client can read beyond the bounds of a buffer, leading to kernel memory corruption. The corrupted kernel memory can cause unexpected system termination, effectively denying service to the affected machine.

Affected Systems

Vulnerable macOS releases are those that precede the fixed versions. Specifically, macOS versions prior to Golden Gate 27, Sequoia 15.8, and Tahoe 26.7 are affected. The flaw resides in Apple’s macOS NFS client component and can impact any system that connects to an NFS server.

Risk and Exploitability

The vulnerability can be exploited remotely by any entity that can host a rogue NFS server that a macOS machine will connect to. Given a CVSS score of 7.5, the flaw is classified as high severity, while the EPSS score of < 1% indicates a low probability of exploitation. Despite the lack of a KEV listing, the risk remains significant in environments that rely on NFS. Successful exploitation could crash the system, so the risk is considered severe.

Generated by OpenCVE AI on September 20, 2026 at 19:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update macOS to the latest release (Golden Gate 27, Sequoia 15.8, or Tahoe 26.7) to apply the bounds‑checking fix.
  • If the NFS client is not required, disable or uninstall it, or block NFS traffic with firewall rules.
  • Monitor system logs for abnormal NFS connections and terminate any unexpected NFS sessions promptly.

Generated by OpenCVE AI on September 20, 2026 at 19:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in macOS NFS Client Leads to Kernel Memory Corruption

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bound Read in macOS NFS Client Leading to Kernel Memory Corruption
Weaknesses CWE-126

Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bound Read in macOS NFS Client Leading to Kernel Memory Corruption
Weaknesses CWE-126

Tue, 15 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-26T23:12:36.847Z

Reserved: 2026-09-01T21:13:17.751Z

Link: CVE-2026-84549

cve-icon Vulnrichment

Updated: 2026-09-17T16:01:54.695Z

cve-icon NVD

Status : Modified

Published: 2026-09-14T21:17:31.030

Modified: 2026-09-27T00:16:35.127

Link: CVE-2026-84549

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:45:02Z

Weaknesses