CVE-2026-84616
PoC massType confusion flaw in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS causes system crashes
CVE-2026-84616 is a type confusion memory-handling flaw in Apple's operating systems, assigned by Apple's product security team. It is triggered by a malicious app running locally on the device, which can confuse data types in memory and crash the system. The stated impact is unexpected system termination — effectively a local denial-of-service — rather than code execution or data theft. All users of iPhone, iPad, Mac, Apple TV, Apple Vision Pro and Apple Watch running versions older than the fixed releases are affected. Exploitation has not been confirmed in the wild (EPSS ~0.2%, no CISA KEV entry), but one public proof-of-concept repository exists and the CVSS score is still pending.
What to do: Update devices to the fixed releases: iOS/iPadOS 26.7 or 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27 and watchOS 27. Because exploitation requires running a local app, avoid installing untrusted or sideloaded apps until patched. Enterprise administrators should use MDM reporting to inventory OS versions across managed fleets and prioritize devices left on older branches (e.g., macOS Sequoia earlier than 15.8).
| Apple iOS | all versions prior to 26.7 (fixed in iOS 26.7 and iOS 27) |
| Apple iPadOS | all versions prior to 26.7 (fixed in iPadOS 26.7 and iPadOS 27) |
| Apple macOS Sequoia | all versions prior to 15.8 (fixed in macOS Sequoia 15.8) |
| Apple macOS Tahoe | all versions prior to 26.7 (fixed in macOS Tahoe 26.7) |
| Apple macOS Golden Gate | all versions prior to 27 (fixed in macOS Golden Gate 27) |
| Apple tvOS | all versions prior to 27 (fixed in tvOS 27) |
| Apple visionOS | all versions prior to 27 (fixed in visionOS 27) |
| Apple watchOS | all versions prior to 27 (fixed in watchOS 27) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.
In the news0 stories
No ingested article mentions this CVE yet.