A macOS SMB kernel vulnerability, CVE-2026-84543, has been publicly disclosed with full details and a proof-of-concept (PoC) exploit. The flaw resides in SMBFS, macOS’s SMB filesystem, and can cause a kernel panic when mounting a malicious SMB server share. The PoC was released by researcher Peter Malone and runs a crafted SMB server on loopback; Apple has patched the issue in the September 2026 security updates, and Malone notes the PoC is expected to kernel-panic and reboot an affected Mac. At the time of reporting, there were no confirmed exploits in the wild.
The advisory lists affected macOS versions as prior to 15.8, 26.7, and 27, with patches delivered in macOS 15.8, 26.7, and 27 (Golden Gate 27, Tahoe 26.7, Sequoia 15.8). The vulnerability is rated CVSS 7.5 (High, v3). Public evidence describes an out-of-bounds-like condition caused by a mis-handled group count during SMB1 mounting: a server can send a count that leads to a lost or mismatched group array, and subsequent attribute lookups may dereference a NULL pointer, triggering a kernel panic.
The PoC code is available in Malone’s GitHub repository, and Apple advises updating to the patched releases and avoiding SMB shares from untrusted networks until patched.