TL;DR
Researcher Peter Malone has published full details and proof-of-concept code for CVE-2026-84543, a macOS SMB kernel vulnerability. A malicious SMB server can crash a Mac’s kernel when the Mac mounts one of its shares. Apple fixed the flaw on September 14, 2026, and paid a $20,000 bounty.
- CVE: CVE-2026-84543
- CVSS: 7.5 (High · CVSSv3)
- Product: Apple macOS
- Affected: < 15.8, < 26.7, < 27
- Status: No confirmed exploitation yet
- Patched in: 15.8, 26.7, 27
- EPSS: 0.4% (30-day)
- Action: Update to 15.8, 26.7, 27 now
Too many Apple alerts in your inbox? Switch to one weekly digest, sorted by severity.
Try Team free for 14 daysWhy This macOS SMB Kernel Vulnerability Matters
SMB is the standard protocol Macs use to reach network file shares. That makes the attack surface common in offices, schools, and home networks. The flaw is also reachable from the network, since the bad data comes from the server side.
Apple’s advisory rates the impact plainly: “Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory.” Apple scored it CVSS 7.5. The public PoC uses a guest session, so it needs no username or password. However, the Mac still has to connect to the malicious share.
How the Attack Works
The bug lives in SMBFS, the macOS SMB filesystem. During an SMB1 mount, macOS asks the server for identity details, including how many supplementary groups the user belongs to. The kernel stores that count before it checks it.
A malicious server can send a count too large to allocate. The size check correctly rejects it, but the cleanup code then leaves the rejected count in place. As Malone writes, “A value rejected by one function remains live and is trusted later by another.” The mount ends up with a group count but no group array.
Later, when SMBFS looks up file attributes, it walks that missing array. According to the analysis, “the next file-attribute lookup trusted that inconsistent state, read through a NULL pointer, and panicked the machine.” Malone also observed a boot-randomized kernel value appearing in several registers at the time of the panic.
Public Proof-of-Concept
The vulnerability details and PoC code are now public. Malone released them in his CVE-2026-84543 GitHub repository. The PoC runs a crafted SMB server on loopback, and Malone warns that it “is expected to kernel-panic and reboot an affected Mac.” No exploitation in the wild has been confirmed.
Affected Versions
Malone reproduced the flaw on Apple silicon running macOS Tahoe 26.4 and on macOS 26.5 beta 4. Apple’s advisory lists fixes for three release lines, which covers Macs that have not yet installed the September updates.
Patch and Mitigation Steps
Update to macOS Golden Gate 27, macOS Tahoe 26.7, or macOS Sequoia 15.8. Apple describes the fix in its macOS security update notes as “improved bounds checking.” Until every Mac is patched, avoid connecting to SMB shares from untrusted networks or unknown servers. Because the PoC is public, patching this macOS SMB kernel vulnerability should not wait.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!