Description
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted file may result in disclosure of process memory.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory disclosure via integer overflow
Action: Immediate patch
AI Analysis

Impact

An integer overflow flaw was discovered in several Apple operating systems. When a maliciously crafted file is processed, the system allocates memory incorrectly, potentially exposing the contents of process memory. This weakness is a classic integer overflow (CWE‑190) that leads to a data disclosure vulnerability.

Affected Systems

The vulnerability affects devices running iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Earlier versions of these operating systems remain vulnerable until patched.

Risk and Exploitability

The vulnerability can lead to disclosure of process memory, but the CVSS score is 6.5, indicating a moderate impact. The EPSS score is below 1%, implying a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a maliciously crafted file, so the attack vector is likely local or remote file upload, depending on context. Devices that frequently accept untrusted files, such as macOS systems with Gatekeeper disabled, present the highest risk.

Generated by OpenCVE AI on September 20, 2026 at 21:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the operating system to the latest available patched release: iOS 26.7 or newer, iPadOS 26.7 or newer, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, or watchOS 27.
  • On macOS enforce Gatekeeper and require code signing to restrict execution of untrusted binaries.
  • If an update cannot be applied immediately, avoid opening or executing files from untrusted or unknown origins until the patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 21:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow Exploit in Apple Operating Systems Leads to Memory Disclosure

Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow Causing Process Memory Disclosure in Apple Operating Systems
Weaknesses CWE-200

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow Causing Process Memory Disclosure in Apple Operating Systems
Weaknesses CWE-190
CWE-200

Tue, 15 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted file may result in disclosure of process memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T17:12:08.993Z

Reserved: 2026-09-01T20:46:41.496Z

Link: CVE-2026-84487

cve-icon Vulnrichment

Updated: 2026-09-15T17:11:29.353Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:26.547

Modified: 2026-09-16T18:41:57.237

Link: CVE-2026-84487

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:45:04Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound