CVE-2026-84611
massOut-of-Bounds Write in Apple 3D Model Parsing Affects iOS, macOS, visionOS, watchOS
An out-of-bounds write (CWE-787) in Apple's 3D model processing code can corrupt memory when a maliciously crafted 3D model is parsed. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:R, 7.3 High) indicates a local attack that requires the victim to open or preview the malicious model file, but needs only low privileges to succeed. Successful exploitation could yield memory corruption with high impact on confidentiality, integrity, and availability, plausibly including code execution in the context of the app rendering the model. The flaw spans Apple's major platforms — iOS/iPadOS, macOS (Sequoia, Tahoe, and Golden Gate branches), tvOS, visionOS, and watchOS — and was fixed with improved bounds checking in the versions listed by Apple. No public proof-of-concept is known and the issue is not in CISA's KEV catalog, so no exploitation in the wild has been reported.
What to do: Patch to the fixed releases: iOS/iPadOS 26.7 or 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. Until updated, avoid opening unsolicited 3D model files or AR/model content received via messages, mail, or untrusted sources. MDM and IT administrators should verify OS patch compliance across managed fleets of all affected Apple device types.
| Apple iOS | versions prior to iOS 26.7 (26.x line) and prior to iOS 27 |
| Apple iPadOS | versions prior to iPadOS 26.7 (26.x line) and prior to iPadOS 27 |
| Apple macOS Sequoia | versions prior to macOS Sequoia 15.8 |
| Apple macOS Tahoe | versions prior to macOS Tahoe 26.7 |
| Apple macOS Golden Gate | versions prior to macOS Golden Gate 27 |
| Apple tvOS | versions prior to tvOS 27 |
| Apple visionOS | versions prior to visionOS 27 |
| Apple watchOS | versions prior to watchOS 27 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption.
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.