CVE-2026-43687 is a kernel memory-handling vulnerability in NFS client processing affecting Apple operating systems. Connecting an affected device to a malicious NFS server can trigger the flaw and disclose kernel memory. Available reporting characterizes the underlying condition as a use-after-free; Apple addressed it through improved memory handling.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file repository contains a self-contained, operational proof of concept and supporting reverse-engineering documentation for CVE-2026-43687, an Apple NFS client access-cache race. The principal executable is poc.sh, a Bash script that emits an embedded Python NFSv3/RPC server and a dtrace monitoring script. The malicious server rotates UID attributes returned to the client, forcing access-cache expansion/reallocation, while multiple local users repeatedly invoke access(2) through test -r and test -w on an NFS-mounted file. Dtrace observes changes to the vulnerable nfsnode+0x158 cache field during _nfs_vnop_access. Documentation explains that macOS 26.7 moves the cache fields and introduces an lck_rw_t lock, preventing the observed race. Supporting files provide the vulnerable-versus-patched disassembly comparison, runtime artifacts, captured race output, environment details, and protocol implementation notes such as valid ACCESS post_op_attr encoding and AppleDouble LOOKUP handling. The PoC is configured for localhost by default but its bind address and ports are configurable; it demonstrates a kernel-memory-disclosure race condition only and does not implement memory extraction or code execution.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability addressed in Apple TV version 27.
A memory-handling vulnerability in Apple NFS client functionality that could allow disclosure of kernel memory when a device connects to a malicious NFS server.
An unspecified vulnerability addressed in Apple iOS 26.7.
NFS-related kernel-memory disclosure.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.