ZeroHour

CVE-2026-84515

mass

Out-of-Bounds Write in Apple macOS SMB Client Enables Kernel Memory Corruption

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-84515 is an out-of-bounds write (CWE-787) in the macOS kernel's SMB client code that Apple fixed with improved bounds checking. The flaw is triggered when a Mac connects to a malicious SMB file server, such as a hostile network share an attacker lures a user into mounting via a link, a spoofed NAS, or a man-in-the-middle position. Successful exploitation corrupts kernel memory, which per the CVSS 3.1 score of 7.8 (C:H/I:H/A:H) can yield kernel-level code execution and full compromise of confidentiality, integrity, and availability on the affected Mac. All users running macOS Sequoia before 15.8, macOS Tahoe before 26.7, and macOS Golden Gate before 27 are affected. No public proof-of-concept is known and the issue is not on the CISA KEV catalog, so exploitation is presumed none_known at this time.

What to do: Patch immediately: upgrade to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27, and push these updates via MDM in enterprise fleets. Instruct users not to mount SMB shares or click smb:// links from untrusted networks or unknown servers, and audit for unexpected outbound SMB (port 445) connections or auto-mounted network shares on managed devices. No workaround fully mitigates a kernel memory-corruption bug, so updating is the primary defense.

Affected
Apple macOS Sequoiabefore 15.8 (fixed in 15.8)
Apple macOS Tahoebefore 26.7 (fixed in 26.7)
Apple macOS Golden Gatebefore 27 (fixed in 27)
Estimated exposure
massTens of millions to ~100M+ Macs, since Sequoia and Tahoe are the two most recent macOS major releases — Apple's installed base exceeds 100M active Macs and the affected versions are the current-generation macOS releases, so the majority of unpatched, internet-connected Macs are plausibly exposed to this client-side flaw.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to kernel memory corruption.

Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.