ZeroHour

CVE-2026-84505

mass

Out-of-Bounds Write in macOS Lets Local Apps Escalate to Root

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-84505 is an out-of-bounds write (CWE-787) caused by insufficient bounds checking in Apple's macOS, fixed with improved bounds checks in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. The flaw is triggered locally: a malicious or compromised app already running on a Mac with normal user privileges can corrupt memory to execute code with root privileges. Successful exploitation gives the attacker full control of the host (high impact to confidentiality, integrity, and availability), making it a valuable privilege-escalation component for malware that has already gained a foothold. Any Mac running a macOS release older than the fixed versions listed above is affected; the bug cannot be triggered remotely on its own. No public proof of concept is known, the issue is not on CISA's KEV list, and no in-the-wild exploitation has been reported.

What to do: Patch promptly by updating to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 or later via System Settings > General > Software Update, and confirm fleet-wide compliance in MDM. Because exploitation requires a local app with user-level privileges, keep Gatekeeper and notarization enforcement enabled and restrict software installation to trusted sources. Watch for Apple's advisory for any update to exploitation status, since local root escalations are commonly chained by post-compromise malware.

Affected
Apple macOS Sequoiaversions prior to 15.8 (fixed in 15.8)
Apple macOS Tahoeversions prior to 26.7 (fixed in 26.7)
Apple macOS Golden Gateversions prior to 27 (fixed in 27)
Estimated exposure
masstens of millions of Macs (macOS installed base exceeds 100 million active devices, minus those already on the patched builds) — Apple has publicly cited an active installed base of well over 100 million Macs, and only machines already running the specific fixed releases (15.8, 26.7, or 27) are protected, so the unpatched population is plausibly in the tens of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

Vendors
apple
Products
macos
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.