DIRAS TAKE
Urgent — public exploit code exists and the flaw can be triggered without authentication by a remote SMB server, so patch exposed macOS hosts promptly or block untrusted SMB servers.
What is CVE-2026-84543?
A remote attacker can trigger an out-of-bounds memory access in macOS by connecting the system to a malicious SMB server, potentially corrupting kernel memory and impacting integrity. CVE-2026-84543 affects macOS Sequoia 15.x before 15.8, Tahoe 26.x before 26.7, and Golden Gate 27.x before 27. Exploitation requires network access to an SMB server; no authentication or user interaction is required to trigger the flaw.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Which versions of Apple macOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 15.x | before 15.8 | 15.8 |
| 26.x | before 26.7 | 26.7 |
| 27.x | before 27 | 27 |
Is CVE-2026-84543 being exploited?
Public exploit code is available.
How to fix CVE-2026-84543
- Upgrade affected macOS installations to 15.8, 26.7, or 27 as provided by Apple.
- Block or limit SMB access from untrusted networks and avoid mounting SMB shares from unknown servers.
- Monitor system and kernel logs for crashes or suspicious SMB connections and isolate impacted hosts.
- Apply vendor guidance from Apple and verify updates are installed across internet-facing and critical systems.
Frequently asked questions
Is CVE-2026-84543 being actively exploited?
Public exploit code is available for CVE-2026-84543.
Which macOS versions are affected by CVE-2026-84543?
macOS Sequoia 15.x before 15.8, Tahoe 26.x before 26.7, and Golden Gate 27.x before 27 are listed as affected.
Is there a patch for CVE-2026-84543?
Yes; Apple fixed the issue in macOS Sequoia 15.8, Tahoe 26.7, and Golden Gate 27 — update to those releases.
Does CVE-2026-84543 require authentication?
No; the vulnerability can be triggered by connecting to a malicious SMB server without authentication or user interaction.
References
- nvd.nist.gov/vuln/detail/CVE-2026-84543
- cve.org/CVERecord?id=CVE-2026-84543
- support.apple.com/en-us/149035
- support.apple.com/en-us/149042
- support.apple.com/en-us/149043
- All Apple CVEs on CVE Radar
- CVEs published in September 2026