CVE-2026-84505
massOut-of-Bounds Write in macOS Lets Local Apps Escalate to Root
CVE-2026-84505 is an out-of-bounds write (CWE-787) caused by insufficient bounds checking in Apple's macOS, fixed with improved bounds checks in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. The flaw is triggered locally: a malicious or compromised app already running on a Mac with normal user privileges can corrupt memory to execute code with root privileges. Successful exploitation gives the attacker full control of the host (high impact to confidentiality, integrity, and availability), making it a valuable privilege-escalation component for malware that has already gained a foothold. Any Mac running a macOS release older than the fixed versions listed above is affected; the bug cannot be triggered remotely on its own. No public proof of concept is known, the issue is not on CISA's KEV list, and no in-the-wild exploitation has been reported.
What to do: Patch promptly by updating to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 or later via System Settings > General > Software Update, and confirm fleet-wide compliance in MDM. Because exploitation requires a local app with user-level privileges, keep Gatekeeper and notarization enforcement enabled and restrict software installation to trusted sources. Watch for Apple's advisory for any update to exploitation status, since local root escalations are commonly chained by post-compromise malware.
| Apple macOS Sequoia | versions prior to 15.8 (fixed in 15.8) |
| Apple macOS Tahoe | versions prior to 26.7 (fixed in 26.7) |
| Apple macOS Golden Gate | versions prior to 27 (fixed in 27) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
- Vendors
- apple
- Products
- macos
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.