Executive brief
macOS is vulnerable to a use-after-free bug in its SMB network share handling that can crash the system when mounting a maliciously crafted network share. An attacker on the same network could exploit this to cause a denial of service, disrupting user work and availability of affected Mac computers.
Technical details
A use-after-free memory vulnerability exists in macOS's SMB (Server Message Block) network share mounting code. The vulnerability is triggered when a user mounts a maliciously crafted SMB network share, leading to system termination (denial of service). The attack vector is adjacent network, requiring the attacker to be on the same network segment or able to serve malicious SMB shares. The fix involves improved memory management to prevent the use-after-free condition. The vulnerability is patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched