vulns.co
/
GKData.io MCP

MEMemory safety and parser contracts · 2 min read

macOS SMBFS error handling left inconsistent kernel parser state

A rejected network response left inconsistent filesystem state. The researcher reports a $20,000 award and subsequent payment.

Read the primary source MEMemory safety and parser contractsReviewed 2026-10-02

Root cause

The parser published a count before validating the associated allocation. Error cleanup did not restore the count and pointer together. The researcher compared parsing, cleanup and later consumption to explain why a failed validation still contaminated trusted kernel state.

Demonstrated impact

A Mac had to connect to a malicious SMB share; guest access was sufficient. The researcher demonstrated kernel panics on Apple silicon. Apple describes possible system termination or kernel-memory corruption. General-purpose code execution was not demonstrated.

Lessons for review

  • Publish related parser fields atomically only after validation succeeds; reset them consistently on every failure.
  • Require consumers to validate compound state, not merely individual fields.
  • Apple reports improved bounds checking; the researcher's temporary-state design is a recommendation, not a verified patch description.

Award and evidence

USD 20,000Bug Bounty · Researcher Reported

One CVE-specific award, not the researcher's cumulative earnings. Source uses $; Apple's official bounty announcement supplies US-dollar program context only.

Read primary public disclosures and corroborating sources; checked individual award scope. No target interaction or exploit reproduction.

  • Payment is researcher-reported, not independently audited.
  • Detailed disclosure publication date remains unknown.
  • Researcher did not independently verify the production patch.
  • USD denomination is inferred from Apple’s 2022 program announcement; the researcher states only $, and no contemporaneous currency-specific payment evidence was reviewed.

Recorded timeline

Public Disclosure
2026-09-14explicit · Vendor security advisory; the researcher README publication date is not established.
Reported
2026-05-03explicit
Awarded
2026-05-14explicit
Fixed
2026-09-14explicit · Golden Gate 27 release and matching SMB advisory.
Paid
2026-06-15explicit

Sources and provenance

  1. CVE-2026-84543: a remote kernel vulnerability in macOS SMBFS Peter Malone · reviewed 2026-10-02
  2. About the security content of macOS Golden Gate 27 Apple · reviewed 2026-10-02
  3. Apple expands industry-leading commitment to protect users from highly targeted mercenary spyware Apple · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software