ZeroHour

CVE-2026-84632

mass

3D Model Memory Corruption in Apple iOS, macOS, watchOS, and visionOS

CVSS 3.1
7.3 high
EPSS
Published
()
Modified
AI analysis

A memory corruption flaw (CWE-120 buffer overflow) exists in Apple's processing of 3D models across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The attack is local and requires user interaction: a victim must open or preview a maliciously crafted 3D model file, likely delivered via messaging, email, AirDrop, or a downloaded file. Successful exploitation can corrupt memory and potentially lead to arbitrary code execution, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.3). Any Apple device running an OS version older than the fixed releases listed below is affected. No public proof of concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and exploitation is not currently known.

What to do: Patch all Apple devices to the fixed releases: iOS/iPadOS 26.7 or 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. Enable automatic security updates across managed fleets to close the gap as rollouts complete. Because the flaw requires a user to open a malicious 3D model file, advise users not to open or preview unsolicited 3D model attachments or downloads from untrusted sources.

Affected
Apple iOSversions prior to iOS 26.7 (fixed in iOS 26.7 and iOS 27)
Apple iPadOSversions prior to iPadOS 26.7 (fixed in iPadOS 26.7 and iPadOS 27)
Apple macOS Sequoiaversions prior to macOS Sequoia 15.8
Apple macOS Tahoeversions prior to macOS Tahoe 26.7
Apple macOS Golden Gateversions prior to macOS Golden Gate 27
Apple tvOSversions prior to tvOS 27
Apple visionOSversions prior to visionOS 27
Apple watchOSversions prior to watchOS 27
Estimated exposure
massplausibly several hundred million to over 1 billion unpatched devices across iPhone, iPad, Mac, Apple TV, Apple Watch, and Vision Pro — Apple publicly reports more than 2 billion active devices in use, and the flaw exists in 3D model processing on every major Apple platform prior to the listed patches, making the unpatched population a large fraction of that installed base.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption.

Weakness
CWE-120
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.