
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28835 is a use-after-free vulnerability in the SMB (Server Message Block) client component of Apple macOS that can cause system termination when a user mounts a maliciously crafted SMB network share. It was disclosed and patched on March 24, 2026, as part of Apple's March 2026 security updates. Affected versions include macOS Sonoma (prior to 14.8.5), macOS Sequoia (prior to 15.7.5), and macOS Tahoe (prior to 26.4). The vulnerability was discovered by Christian Kohlschütter and carries a CVSS v3.1 base score of 6.5 (Medium) (Apple Sequoia Advisory, Apple Sonoma Advisory, Apple Tahoe Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring within macOS's SMB network share handling code where memory is accessed after it has been freed, leading to memory corruption. The attack vector is network-based and requires user interaction — specifically, a user must mount a maliciously crafted SMB network share served by an attacker-controlled server. No authentication or elevated privileges are required on the attacker's side. The fix was implemented through improved memory management in the SMB subsystem (Apple Sequoia Advisory, Apple Sonoma Advisory, Apple Tahoe Advisory).
Successful exploitation results in system termination (kernel panic / crash), constituting a denial-of-service condition. There is no evidence of confidentiality or integrity impact — the vulnerability's primary consequence is availability loss, causing the affected macOS system to crash when the malicious SMB share is mounted. The attack requires user interaction but no authentication, meaning any network-accessible macOS system whose user can be socially engineered into mounting a rogue SMB share is at risk (Apple Sonoma Advisory, Apple Tahoe Advisory).
mount_smbfs), or an automated mechanism./Library/Logs/DiagnosticReports/ or via Console.app) referencing SMB-related kernel extensions or nsmb processes around the time of system crash.smbfs, nsmb_vc, or related kernel modules).log show) showing SMB mount attempts (mount_smbfs) to unknown or suspicious server addresses immediately preceding a system reboot.Apple has released patches addressing this vulnerability in macOS Sonoma 14.8.5, macOS Sequoia 15.7.5, and macOS Tahoe 26.4, all released on March 24, 2026. Users should update their macOS systems to these versions or later via System Settings > General > Software Update. As a precautionary workaround prior to patching, users should avoid mounting SMB network shares from untrusted, unknown, or suspicious sources (Apple Sequoia Advisory, Apple Sonoma Advisory, Apple Tahoe Advisory).
The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Apple products from the March 2026 update cycle, including this SMB flaw. A Reddit thread in r/macsysadmin reported a 100% reproducible kernel panic on macOS Tahoe 26.4 related to SMB share mounting, suggesting the vulnerability was observable in practice before or around the patch release. A technical blog post titled "MAD BUGS: An Apple Kernel Bug Brought to You by Microsoft" on blog.calif.io discussed the SMB-related kernel bug in detail, drawing community attention to the underlying issue (blog.calif.io).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."