CVE-2026-84515

Apple · macOS

An out-of-bounds write vulnerability in macOS allows local attackers to cause kernel memory corruption by connecting to a malicious SMB server.

Executive summary

An out-of-bounds write vulnerability in Apple macOS poses a high risk of kernel memory corruption when a user connects to a malicious SMB server.

Vulnerability

This is an out-of-bounds write vulnerability occurring within the kernel due to improper bounds checking. An attacker with local access can trigger this flaw by enticing a user to connect to a malicious SMB server.

Business impact

The exploitation of this vulnerability leads to kernel memory corruption, which can result in a total loss of system integrity and availability. Given the CVSS score of 7.8, this vulnerability is classified as high severity as it permits an attacker to potentially execute arbitrary code with kernel-level privileges. Such a compromise grants the attacker complete control over the affected system, creating significant risks for data confidentiality and overall organizational security.

Remediation

Immediate Action: Update all affected macOS systems to version 15.8, 26.7, or 27 immediately to apply the necessary bounds checking improvements.

Proactive Monitoring: Monitor system logs for unexpected crashes or kernel panics, particularly following network connection events involving file sharing protocols.

Compensating Controls: Restrict outbound SMB connections to untrusted or external networks via host-based firewalls or network access control lists to prevent connections to malicious servers.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates a prompt response from IT administrators. Organizations should prioritize patching all macOS endpoints to the specified fixed versions to eliminate the risk of kernel memory corruption. Until patches can be deployed, users should be cautioned against connecting to unknown or untrusted SMB shares.

More Apple CVEs all →

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.8 (3.1)
  4. Analyst report written

Sources