Junglewise Threat Intelligence

CVE-2026-65365: Apple macOS SMB out-of-bounds read in kernel

CVE-2026-65365 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Apple macOS contains an out-of-bounds read vulnerability in its SMB (file sharing) protocol handler that can be exploited when connecting to a malicious network share. An attacker operating a malicious SMB server could expose sensitive kernel memory to users who connect to the share, potentially leaking confidential system information.

Technical details

An out-of-bounds read vulnerability exists in macOS's SMB protocol implementation, allowing a reading of kernel memory beyond allocated buffer boundaries. The vulnerability is triggered when a user connects to a malicious SMB share that provides crafted responses. The attack requires user interaction (connecting to a network share) and network reachability to the attacker-controlled SMB server. An attacker can leverage this to disclose kernel memory that may contain sensitive information such as ASLR bypass data or other privileged memory regions. The issue was fixed with improved bounds checking in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed: CVE-2026-65365 disclosed; patches released
  • 2026-09-14: patched: macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7 released

References

Related threats