Executive brief
AFP (Apple Filing Protocol) is a network file sharing system used to connect to remote file servers. CVE-2026-43815 is a buffer overflow vulnerability that allows an attacker operating a malicious AFP server to corrupt kernel memory when a macOS system connects to it, potentially leading to system crashes or unauthorized access to sensitive kernel data. This vulnerability affects multiple versions of macOS and requires no user action beyond connecting to a compromised network resource.
Technical details
CVE-2026-43815 is a buffer overflow vulnerability in the afpfs (Apple Filing Protocol File System) component of macOS. The flaw exists in the network file system handling code and is triggered when a macOS system connects to a malicious AFP server that sends specially crafted responses. The vulnerability allows an attacker with control of the server to write beyond buffer boundaries in kernel memory, potentially causing kernel memory corruption, denial of service, or privilege escalation. The attack vector is network-based and requires only that the target connects to the attacker's malicious AFP server; no authentication or user interaction beyond the connection attempt is required. The vulnerability has been patched in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6 through improved bounds checking in the afpfs code.
Affected products
- Apple macOS Sequoia before 15.7.8
- Apple macOS Sonoma before 14.8.8
- Apple macOS Tahoe before 26.6
Timeline
- 2026-09-14: disclosed: CVE-2026-43815 publicly disclosed
- 2026-07-27: patched: Fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6