CVE-2026-28835
macOS vulnerability analysis and mitigation

Overview

CVE-2026-28835 is a use-after-free vulnerability in the SMB (Server Message Block) client component of Apple macOS that can cause system termination when a user mounts a maliciously crafted SMB network share. It was disclosed and patched on March 24, 2026, as part of Apple's March 2026 security updates. Affected versions include macOS Sonoma (prior to 14.8.5), macOS Sequoia (prior to 15.7.5), and macOS Tahoe (prior to 26.4). The vulnerability was discovered by Christian Kohlschütter and carries a CVSS v3.1 base score of 6.5 (Medium) (Apple Sequoia Advisory, Apple Sonoma Advisory, Apple Tahoe Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring within macOS's SMB network share handling code where memory is accessed after it has been freed, leading to memory corruption. The attack vector is network-based and requires user interaction — specifically, a user must mount a maliciously crafted SMB network share served by an attacker-controlled server. No authentication or elevated privileges are required on the attacker's side. The fix was implemented through improved memory management in the SMB subsystem (Apple Sequoia Advisory, Apple Sonoma Advisory, Apple Tahoe Advisory).

Impact

Successful exploitation results in system termination (kernel panic / crash), constituting a denial-of-service condition. There is no evidence of confidentiality or integrity impact — the vulnerability's primary consequence is availability loss, causing the affected macOS system to crash when the malicious SMB share is mounted. The attack requires user interaction but no authentication, meaning any network-accessible macOS system whose user can be socially engineered into mounting a rogue SMB share is at risk (Apple Sonoma Advisory, Apple Tahoe Advisory).

Exploitation steps

  1. Set up a malicious SMB server: The attacker configures a rogue SMB server (e.g., using Samba or a custom implementation) that serves a specially crafted network share designed to trigger the use-after-free condition in macOS's SMB client.
  2. Social engineering: The attacker lures a target macOS user into connecting to the malicious SMB share — for example, via a phishing email, malicious link, or by being on the same network and advertising the share via mDNS/Bonjour.
  3. User mounts the share: The victim mounts the malicious SMB share through Finder (Go > Connect to Server), the Terminal (mount_smbfs), or an automated mechanism.
  4. Trigger the use-after-free: The crafted SMB server response triggers the memory management flaw in the macOS SMB client, causing a use-after-free condition.
  5. System termination: The corrupted memory state causes a kernel panic, resulting in immediate system crash and reboot — achieving denial of service (Apple Sonoma Advisory, Apple Tahoe Advisory).

Indicators of compromise

  • Logs: Unexpected kernel panic logs (/Library/Logs/DiagnosticReports/ or via Console.app) referencing SMB-related kernel extensions or nsmb processes around the time of system crash.
  • Logs: System crash reports showing stack traces involving SMB client code (e.g., smbfs, nsmb_vc, or related kernel modules).
  • Network: Outbound SMB connections (TCP port 445 or 139) to unfamiliar or external IP addresses initiated by the user's system shortly before a crash event.
  • Logs: macOS Unified Log entries (via log show) showing SMB mount attempts (mount_smbfs) to unknown or suspicious server addresses immediately preceding a system reboot.

Mitigation and workarounds

Apple has released patches addressing this vulnerability in macOS Sonoma 14.8.5, macOS Sequoia 15.7.5, and macOS Tahoe 26.4, all released on March 24, 2026. Users should update their macOS systems to these versions or later via System Settings > General > Software Update. As a precautionary workaround prior to patching, users should avoid mounting SMB network shares from untrusted, unknown, or suspicious sources (Apple Sequoia Advisory, Apple Sonoma Advisory, Apple Tahoe Advisory).

Community reactions

The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Apple products from the March 2026 update cycle, including this SMB flaw. A Reddit thread in r/macsysadmin reported a 100% reproducible kernel panic on macOS Tahoe 26.4 related to SMB share mounting, suggesting the vulnerability was observable in practice before or around the patch release. A technical blog post titled "MAD BUGS: An Apple Kernel Bug Brought to You by Microsoft" on blog.calif.io discussed the SMB-related kernel bug in detail, drawing community attention to the underlying issue (blog.calif.io).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management