
New MAD Bugs drop: we had Claude reverse Apple's macOS 26.4 SMB patch end-to-end and build a kernel PoC from just the advisory. CVE-2026-28825, heap OOB in smbfs.kext, reachable by clicking on any smb:// link in Finder, Safari, or Messages. Root cause is a missing bounds check on an attacker-controlled compress length. The fun part is in Apple's own source: the check was there. A developer wrapped it in #if 0 because Windows Server kept tripping it, left a comment about it, and shipped. The entire reversing, root-cause analysis, and PoC build was driven autonomously by Claude. We handed it the advisory URL and came back to a working panic. It even blamed Microsoft for everything. Full writeup: https://open.substack.com/pub/calif/p/mad-bugs-an-apple-kernel-bug-brought?r=26yra9&utm_campaign=post&utm_medium=web
Post summary
The post announces a new MAD Bugs release featuring a kernel proof‑of‑concept for CVE‑2026‑28825, detailing a heap OOB flaw in Apple’s SMB implementation, but provides no evidence of active exploitation or patching.




