Executive brief
macOS is the operating system used on Apple computers. A flaw in the kernel's handling of SMB (network file sharing) connections allows an attacker to cause system crashes or corrupt kernel memory by connecting to a malicious SMB server. This could lead to system instability or provide a stepping stone for further attacks.
Technical details
This vulnerability is an out-of-bounds access issue in macOS kernel SMB handling, addressed through improved bounds checking. The attack vector involves connecting to a malicious SMB server without requiring prior authentication or special privileges. Successful exploitation may result in unexpected system termination or kernel memory corruption. The vulnerability is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, released on September 14, 2026.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed: CVE-2026-84543 disclosed
- 2026-09-14: patched: Patches released: macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7