Junglewise Threat Intelligence

CVE-2026-84549: Apple macOS NFS out-of-bounds read

CVE-2026-84549 · Severity: high · CVSS 7.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

macOS systems contain a vulnerability in NFS (Network File System) handling that can cause the system to crash or corrupt kernel memory when connecting to a malicious NFS server. This could allow an attacker to disrupt system availability or potentially gain elevated control over the computer by exploiting memory corruption on any machine that mounts network file shares.

Technical details

An out-of-bounds read vulnerability exists in macOS NFS client implementation, addressed with improved bounds checking. The vulnerability is triggered when a system connects to a malicious NFS server that sends specially crafted responses. The attack requires network connectivity to an attacker-controlled NFS server; no authentication or local access is required. Successful exploitation can cause unexpected system termination (denial of service) or corrupt kernel memory. The issue is patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed: Published in Apple security advisory
  • 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7

References

Related threats