Root cause
The parser published a count before validating the associated allocation. Error cleanup did not restore the count and pointer together. The researcher compared parsing, cleanup and later consumption to explain why a failed validation still contaminated trusted kernel state.
Demonstrated impact
A Mac had to connect to a malicious SMB share; guest access was sufficient. The researcher demonstrated kernel panics on Apple silicon. Apple describes possible system termination or kernel-memory corruption. General-purpose code execution was not demonstrated.
Lessons for review
- Publish related parser fields atomically only after validation succeeds; reset them consistently on every failure.
- Require consumers to validate compound state, not merely individual fields.
- Apple reports improved bounds checking; the researcher's temporary-state design is a recommendation, not a verified patch description.
Award and evidence
One CVE-specific award, not the researcher's cumulative earnings. Source uses $; Apple's official bounty announcement supplies US-dollar program context only.
Read primary public disclosures and corroborating sources; checked individual award scope. No target interaction or exploit reproduction.
- Payment is researcher-reported, not independently audited.
- Detailed disclosure publication date remains unknown.
- Researcher did not independently verify the production patch.
- USD denomination is inferred from Apple’s 2022 program announcement; the researcher states only $, and no contemporaneous currency-specific payment evidence was reviewed.
Recorded timeline
- Public Disclosure
- 2026-09-14explicit · Vendor security advisory; the researcher README publication date is not established.
- Reported
- 2026-05-03explicit
- Awarded
- 2026-05-14explicit
- Fixed
- 2026-09-14explicit · Golden Gate 27 release and matching SMB advisory.
- Paid
- 2026-06-15explicit
Sources and provenance
- CVE-2026-84543: a remote kernel vulnerability in macOS SMBFS Peter Malone · reviewed 2026-10-02
- About the security content of macOS Golden Gate 27 Apple · reviewed 2026-10-02
- Apple expands industry-leading commitment to protect users from highly targeted mercenary spyware Apple · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.