CVE-2026-84543

Apple · macOS

A memory safety flaw in macOS allows unauthenticated attackers to trigger kernel memory corruption or system crashes by enticing a user to connect to a malicious SMB server.

Executive summary

A critical out-of-bounds access vulnerability in macOS allows unauthenticated attackers to cause kernel memory corruption or unexpected system termination through malicious SMB server connections.

Vulnerability

The vulnerability is an out-of-bounds access issue resulting from insufficient bounds checking when processing network requests. An unauthenticated attacker can exploit this by hosting a malicious SMB server and tricking a target into connecting, leading to memory corruption or denial of service.

Business impact

The potential for kernel memory corruption poses a significant risk to system integrity and stability. Successful exploitation could lead to arbitrary code execution within the kernel or repeated system crashes, resulting in prolonged downtime and potential unauthorized access to sensitive system data. With a CVSS score of 7.5, this high-severity vulnerability requires immediate attention to prevent operational disruption.

Remediation

Immediate Action: Update all Apple macOS installations to version 15.8, 26.7, or 27 immediately to apply the necessary bounds checking improvements.

Proactive Monitoring: Monitor network traffic for connections to untrusted or unauthorized SMB servers and review system logs for recurring kernel panic events.

Compensating Controls: Restrict outbound SMB traffic (TCP port 445) at the network perimeter to trusted endpoints only to prevent users from connecting to malicious external servers.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of potential kernel memory corruption, organizations should treat this update as high priority. Administrators must ensure all macOS devices are patched to the specified versions to eliminate the underlying memory safety flaw and prevent potential exploitation by malicious SMB servers.

More Apple CVEs all →

History

CVE Brief tracked this CVE 4 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.5 (3.1)
  4. Analyst report written

Sources