CVE-2026-84516
massOut-of-Bounds Read in macOS File Processing Allows Memory Disclosure
CVE-2026-84516 is an out-of-bounds read (CWE-125) in macOS that is triggered when the operating system processes a maliciously crafted file, such as an emailed attachment or downloaded document. Successful exploitation can disclose portions of process memory to the attacker or cause unexpected application termination, affecting availability and confidentiality but not integrity. The attack requires no privileges but does require user interaction, meaning the victim must open or otherwise trigger processing of the malicious file. All Macs running macOS Golden Gate prior to version 27, macOS Sequoia prior to 15.8, or macOS Tahoe prior to 26.7 are affected. Apple has patched the issue with improved bounds checking, and no public proof of concept or known in-the-wild exploitation has been reported.
What to do: Update immediately to the fixed release for your installed major version: macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7. Because exploitation requires a victim to process a malicious file, advise users to treat unexpected attachments, downloads, and shared documents with caution. Use MDM or inventory tools to verify patch rollout across managed Mac fleets and check crash logs for unexpected app terminations that could indicate an attempted exploit.
| Apple macOS Golden Gate | versions prior to 27 |
| Apple macOS Sequoia | versions prior to 15.8 |
| Apple macOS Tahoe | versions prior to 26.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted file may result in unexpected app termination or disclosure of process memory.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.