CVE-2026-84543 is an out-of-bounds access vulnerability in macOS SMB handling. When a macOS system connects to a malicious SMB server, the issue can cause unexpected system termination or corrupt kernel memory. Apple addressed the flaw by improving bounds checking in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file repository contains a Python proof of concept and supporting documentation/evidence for CVE-2026-84543, a remotely triggered macOS SMBFS kernel denial-of-service condition. The primary artifact, poc/smb1_unix_whoami_poc.py (approximately 65 KB), is a standalone threaded TCP SMB1 server using only the Python standard library. It listens on configurable IPv4 address/port values (default 0.0.0.0:445), accepts guest SMB sessions, and serves crafted SMB transaction responses. The trigger abuses SMB_QFS_POSIX_WHOAMI information level 0x0202. An oversized supplementary-group count is parsed into persistent mount state, rejected by an allocation-size check, but not cleared because cleanup only resets the count when a group allocation exists. This leaves ntwrk_cnt_gid attacker-controlled and nonzero while ntwrk_gids remains NULL. A later UNIX_INFO2 (0x020B) response causes SMBFS attribute caching to traverse the claimed group array and dereference the NULL pointer, producing a kernel data abort/panic. The script intentionally keeps an inherited secondary symlink-reply path benign and non-configurable, indicating the public PoC's intended trigger is limited to this vulnerability. The script is tailored to ARM64 macOS: it directly reads the current boot's _COMM_PAGE_ASB_TARGET_KERN_VALUE from the commpage, then inserts that value (or masked portions of it) into controlled SMB response fields. README and evidence files describe observed matching values in x8, x9, x10, x11, x12, and x14 during panic capture. This is provenance instrumentation rather than a data-exfiltration or code-execution capability. Documentation supplies loopback reproduction instructions using mount_smbfs and explicitly warns that affected systems are expected to panic and reboot. No exploit framework, outbound C2, hard-coded remote victim, credential theft, or post-exploitation payload is present.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.