Executive brief
A vulnerability in macOS could allow a malicious file server to crash a user's computer. When a user connects to a specially crafted SMB server (a common protocol for sharing files over a network), the system may terminate unexpectedly. This results in a denial-of-service, potentially causing data loss or interrupting business operations.
Technical details
A memory handling vulnerability exists in the macOS SMB client implementation. The flaw is triggered when the system connects to a malicious SMB server that sends specifically crafted responses. This root cause is a memory management error that leads to a kernel panic or system termination (Denial of Service). The issue was addressed by improving memory handling logic in the affected components. Patches are available in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Affected products
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Sonoma Before 14.8.8
- Apple macOS Tahoe Before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched