Executive brief
macOS is the operating system running on Apple's Mac computers. When connecting to a malicious SMB (file sharing) server, a kernel memory corruption vulnerability could allow an attacker to crash the system or potentially execute code with kernel-level privileges. This affects multiple recent versions of macOS across all Apple silicon Macs.
Technical details
The vulnerability is an out-of-bounds write issue in the macOS kernel's SMB client implementation, addressed through improved bounds checking. The vulnerability is triggered when a system connects to a malicious SMB server that sends crafted packets designed to overflow a buffer. No authentication is required beyond the initial SMB connection, and the attack is network-reachable. Successful exploitation can result in kernel memory corruption leading to denial of service or privilege escalation. The fix is available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, released on September 14, 2026.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched