CVE-2026-84563
massType Confusion in macOS Lets an App Cause Unexpected System Termination
CVE-2026-84563 is a logic flaw (CWE-843, type confusion — access of a resource using an incompatible type) in macOS that Apple addressed with improved type checks. The bug is triggered when a malicious or compromised application runs on an affected Mac and exploits the mishandled resource access to cause unexpected system termination, i.e., a crash or forced shutdown of the device. The CVSS 3.1 base score is 7.5 (high), and Apple's vector rates it network-exploitable with no privileges or user interaction, though the practical impact Apple describes is loss of system availability rather than data compromise. All users running macOS Sequoia before 15.8, macOS Tahoe before 26.7, or macOS Golden Gate before 27 are affected, with fixes shipping in Sequoia 15.8, Tahoe 26.7, and Golden Gate 27. There is no known public proof of concept, no reported in-the-wild exploitation, and the CVE is not on the CISA Known Exploited Vulnerabilities catalog.
What to do: Patch affected Macs to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 as soon as possible, and enable automatic security updates fleet-wide. Because exploitation requires running a malicious or compromised app, keep Gatekeeper and notarization enforcement enabled and restrict software installation to trusted sources, especially for developer and power-user machines that frequently run unsigned or third-party code. Verify after patching that no unexpected system terminations correlate with specific applications, which would be an indicator worth escalating to Apple Product Security.
| Apple macOS Sequoia | prior to 15.8 (fixed in 15.8) |
| Apple macOS Tahoe | prior to 26.7 (fixed in 26.7) |
| Apple macOS Golden Gate | prior to 27 (fixed in 27) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.