ZeroHour

CVE-2026-84516

mass

Out-of-Bounds Read in macOS File Processing Allows Memory Disclosure

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-84516 is an out-of-bounds read (CWE-125) in macOS that is triggered when the operating system processes a maliciously crafted file, such as an emailed attachment or downloaded document. Successful exploitation can disclose portions of process memory to the attacker or cause unexpected application termination, affecting availability and confidentiality but not integrity. The attack requires no privileges but does require user interaction, meaning the victim must open or otherwise trigger processing of the malicious file. All Macs running macOS Golden Gate prior to version 27, macOS Sequoia prior to 15.8, or macOS Tahoe prior to 26.7 are affected. Apple has patched the issue with improved bounds checking, and no public proof of concept or known in-the-wild exploitation has been reported.

What to do: Update immediately to the fixed release for your installed major version: macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7. Because exploitation requires a victim to process a malicious file, advise users to treat unexpected attachments, downloads, and shared documents with caution. Use MDM or inventory tools to verify patch rollout across managed Mac fleets and check crash logs for unexpected app terminations that could indicate an attempted exploit.

Affected
Apple macOS Golden Gateversions prior to 27
Apple macOS Sequoiaversions prior to 15.8
Apple macOS Tahoeversions prior to 26.7
Estimated exposure
masstens to hundreds of millions of Macs worldwide until patched (order of magnitude: 100M+) — Apple's ecosystem comprises well over one billion active devices with macOS representing a substantial share, and this flaw spans three major macOS generations, so the unpatched install base is plausibly in the hundred-million range until…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted file may result in unexpected app termination or disclosure of process memory.

Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.