Executive brief
An integer underflow vulnerability in macOS affects the SMB (file sharing) protocol handler used to connect to network file servers. An attacker operating a malicious SMB server could trigger unexpected system termination (denial of service) on connecting clients. The flaw affects multiple recent macOS releases and has been patched in Golden Gate 27, Sequoia 15.8, and Tahoe 26.7.
Technical details
An integer underflow vulnerability exists in macOS's SMB protocol handler, triggered when connecting to a malicious SMB server. The flaw occurs during input validation of SMB protocol messages, allowing an attacker to craft special packet sequences that cause integer arithmetic to wrap and result in unexpected memory access or process termination. No authentication or special privileges are required—only a network connection to the malicious SMB server. The vulnerability leads to denial of service (system termination); code execution is not indicated. Apple addressed this issue with improved input validation in patched versions.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7