CVE-2026-84543
massOut-of-Bounds Access in Apple macOS SMB Client Enables Kernel Memory Corruption
CVE-2026-84543 is an out-of-bounds read (CWE-125) in the SMB client networking code of macOS, caused by missing bounds checking when processing responses from an SMB server. It is triggered when a vulnerable Mac connects to an attacker-controlled SMB server, such as by mounting a malicious file share or following an smb:// link, with no privileges or user interaction required per the CVSS vector. A successful attack can cause unexpected system termination (kernel panic) or corruption of kernel memory, giving the attacker a high-integrity impact on the affected machine, though no confidentiality impact. All Macs running macOS Sequoia before 15.8, macOS Tahoe before 26.7, and macOS Golden Gate before 27 are affected, since the SMB client ships in every default installation. Apple has released fixes, and there is currently no known exploitation, no public proof of concept, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog.
What to do: Update to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 or later as soon as possible. Advise users not to mount SMB shares from or click smb:// links pointing to untrusted servers, and consider restricting outbound TCP port 445 to approved file servers on managed networks. Investigate any recurring kernel panics that coincide with SMB connections as a possible indicator of targeting.
| Apple macOS Sequoia | < 15.8 |
| Apple macOS Tahoe | < 26.7 |
| Apple macOS Golden Gate | < 27 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.