ZeroHour

CVE-2026-84561

mass

Kernel Double-Free in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-84561 is a double-free memory-corruption flaw (CWE-415) in the kernel of Apple's operating systems, resolved through improved memory management. Although the CVSS vector is scored with a network attack vector, Apple's advisory describes a locally running app as the trigger: a malicious or compromised app on the device can trip the double free in kernel code. The result, per Apple, is unexpected system termination or corruption of kernel memory — a denial-of-service condition, with kernel memory corruption potentially usable as a building block for further exploitation. All users of iPhones, iPads, Macs, Apple TVs, Apple Vision Pro headsets and Apple Watches running versions older than the fixed releases are affected. There is currently no evidence of in-the-wild exploitation, no CISA KEV listing, and no known public proof-of-concept.

What to do: Update devices to iOS/iPadOS 26.7 or 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27 or watchOS 27. Verify fleet OS versions via MDM or Settings > General > Software Update and prioritize user-facing iOS/macOS devices. Until patched, limit risk by avoiding untrusted app installs, since a local app is the documented trigger; no other workaround is available.

Affected
Apple iOSprior to 26.7 and prior to 27 (fixed in iOS 26.7 and iOS 27)
Apple iPadOSprior to 26.7 and prior to 27 (fixed in iPadOS 26.7 and iPadOS 27)
Apple macOS Sequoiaprior to 15.8 (fixed in macOS Sequoia 15.8)
Apple macOS Tahoeprior to 26.7 (fixed in macOS Tahoe 26.7)
Apple macOS Golden Gateprior to 27 (fixed in macOS Golden Gate 27)
Apple tvOSprior to 27 (fixed in tvOS 27)
Apple visionOSprior to 27 (fixed in visionOS 27)
Apple watchOSprior to 27 (fixed in watchOS 27)
Estimated exposure
massroughly 2 billion active Apple devices (iPhone, iPad, Mac, Apple TV, Apple Watch, Vision Pro) on pre-fix OS versions — Apple has publicly reported more than 2 billion active devices, and every device running an OS version older than the fixed releases is affected until patched.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.

Vendors
apple
Products
ipados, iphone os, macos, tvos, visionos, watchos
Weakness
CWE-415
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.