Junglewise Threat Intelligence

CVE-2026-39873: Apple macOS denial of service when connecting to SMB server

CVE-2026-39873 · Severity: info · Published 2026-07-27

Technologies: Apple macOS Tahoe. Vendors: Apple.

Executive brief

A vulnerability in macOS could allow a malicious file server to crash a user's computer. When a user connects to a specially crafted SMB server (a common protocol for sharing files over a network), the system may terminate unexpectedly. This results in a denial-of-service, potentially causing data loss or interrupting business operations.

Technical details

A memory handling vulnerability exists in the macOS SMB client implementation. The flaw is triggered when the system connects to a malicious SMB server that sends specifically crafted responses. This root cause is a memory management error that leads to a kernel panic or system termination (Denial of Service). The issue was addressed by improving memory handling logic in the affected components. Patches are available in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.

Affected products

  • Apple macOS Sequoia Before 15.7.8
  • Apple macOS Sonoma Before 14.8.8
  • Apple macOS Tahoe Before 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats