CVE-2026-84575
massOut-of-Bounds Write in Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS
CVE-2026-84575 is an out-of-bounds write (CWE-787) in Apple's operating systems that was fixed with improved bounds checking in the iOS 27-generation releases. The flaw is triggered when an affected device processes a maliciously crafted file, causing unexpected app termination, and the CVSS 3.1 vector (C:H/I:H/A:H) indicates successful corruption could extend to confidentiality, integrity, and availability, including potential code execution. All versions of iOS, iPadOS, macOS (Sequoia, Tahoe, and Golden Gate lines), tvOS, visionOS, and watchOS prior to the listed fixed releases are affected. This spans essentially the entire modern Apple device ecosystem, from iPhones and Macs to Apple TV, Apple Watch, and Apple Vision Pro. There is no known public proof of concept and the issue is not on the CISA KEV catalog, so exploitation is currently none known.
What to do: Patch all Apple devices to the fixed releases: iOS 27 / iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. In managed fleets, enforce these minimum OS versions via MDM and audit for lagging devices. Advise users to avoid opening files from untrusted sources, since exploitation requires processing a maliciously crafted file on the local device.
| Apple iOS | versions prior to iOS 27 |
| Apple iPadOS | versions prior to iPadOS 27 |
| Apple macOS (Sequoia line) | versions prior to macOS Sequoia 15.8 |
| Apple macOS (Tahoe line) | versions prior to macOS Tahoe 26.7 |
| Apple macOS (Golden Gate line) | versions prior to macOS Golden Gate 27 |
| Apple tvOS | versions prior to tvOS 27 |
| Apple visionOS | versions prior to visionOS 27 |
| Apple watchOS | versions prior to watchOS 27 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted file may lead to unexpected app termination.
- Vendors
- apple
- Products
- ipados, iphone os, macos, tvos, visionos, watchos
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.