Executive brief
macOS systems include a network file system (NFS) client that allows computers to access files on remote servers. A flaw in this component could allow an attacker running a malicious NFS server to crash the system or corrupt kernel memory without authentication. This could lead to system instability, denial of service, or potential privilege escalation.
Technical details
An integer overflow vulnerability exists in the NFS client component of the macOS kernel. The vulnerability is triggered when connecting to a malicious NFS server that sends specially crafted data, leading to unexpected system termination or kernel memory corruption. The attack requires network connectivity to a malicious NFS server but does not require user interaction or authentication on the client system. An attacker can cause denial of service by crashing the kernel or potentially achieve arbitrary code execution by corrupting kernel memory structures. The vulnerability has been patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed: Advisory published on September 14, 2026
- 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 released September 14, 2026