ZeroHour

CVE-2026-84553

mass

Unauthenticated Remote Denial-of-Service (Resource Exhaustion) in Apple macOS

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

This is an unauthenticated, remotely triggerable resource exhaustion flaw (CWE-400) in Apple macOS: a remote attacker can send crafted input that drives excessive resource consumption on the target Mac, degrading performance or causing the system to crash or become unresponsive. The CVSS 3.1 score of 7.5 reflects a network attack vector with low attack complexity and no privileges or user interaction required, with high impact on availability only — confidentiality and integrity are unaffected. Apple fixed the issue with improved input validation in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, so Macs running older builds of these release lines remain exposed. No public proof of concept is known, the flaw is not on CISA's KEV list, and no exploitation in the wild has been reported. The specific vulnerable component within macOS was not disclosed, so any Mac running an unpatched OS version should be treated as potentially attackable over the network.

What to do: Update to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) as soon as possible. In managed fleets, verify that all Macs have applied the security update, and monitor endpoints for unexplained memory pressure, CPU spikes, or crashes. Until patched, limit exposure of unnecessary network services on Macs, since the flaw is remotely triggerable without authentication or user interaction.

Affected
Apple macOS Sequoiaversions before 15.8 (fixed in 15.8)
Apple macOS Tahoeversions before 26.7 (fixed in 26.7)
Apple macOS Golden Gateversions before 27 (fixed in 27)
Estimated exposure
massTens of millions of Macs (order of magnitude), since Apple's active Mac installed base exceeds 100 million devices and a substantial fraction typically lags… — Estimated from Apple's publicly stated installed base of over 100 million active Macs, with the vulnerable pool being devices that have not yet applied the Sequoia 15.8 / Tahoe 26.7 / Golden Gate 27 updates.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause a denial-of-service.

Vendors
apple
Products
macos
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.