CVE-2026-84553
massUnauthenticated Remote Denial-of-Service (Resource Exhaustion) in Apple macOS
This is an unauthenticated, remotely triggerable resource exhaustion flaw (CWE-400) in Apple macOS: a remote attacker can send crafted input that drives excessive resource consumption on the target Mac, degrading performance or causing the system to crash or become unresponsive. The CVSS 3.1 score of 7.5 reflects a network attack vector with low attack complexity and no privileges or user interaction required, with high impact on availability only — confidentiality and integrity are unaffected. Apple fixed the issue with improved input validation in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, so Macs running older builds of these release lines remain exposed. No public proof of concept is known, the flaw is not on CISA's KEV list, and no exploitation in the wild has been reported. The specific vulnerable component within macOS was not disclosed, so any Mac running an unpatched OS version should be treated as potentially attackable over the network.
What to do: Update to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) as soon as possible. In managed fleets, verify that all Macs have applied the security update, and monitor endpoints for unexplained memory pressure, CPU spikes, or crashes. Until patched, limit exposure of unnecessary network services on Macs, since the flaw is remotely triggerable without authentication or user interaction.
| Apple macOS Sequoia | versions before 15.8 (fixed in 15.8) |
| Apple macOS Tahoe | versions before 26.7 (fixed in 26.7) |
| Apple macOS Golden Gate | versions before 27 (fixed in 27) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause a denial-of-service.
- Vendors
- apple
- Products
- macos
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.