Description
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to cause a denial of service.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A buffer overflow caused by insufficient bounds checking allows a crafted input to exceed allocated memory boundaries, which can trigger the operating system to terminate unexpectedly. The flaw is limited to a denial‑of‑service effect and does not provide privilege escalation. The vulnerability is formally identified as CWE‑120.

Affected Systems

Apple iOS on iPhone devices, iPadOS on iPad devices, and macOS on Mac computers are impacted. Specifically, iOS 18.7.10 and 27, and iPadOS 18.7.10 and 27 are vulnerable on iPhones and iPads. On Macs, macOS Golden Gate 27, Sequoia 15.7.8 and Sonoma 14.8.8 are affected. All earlier or pre‑release versions of these operating systems remain susceptible until updated.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating that no active exploitation has been reported. The CVSS score of 5.5 reflects a moderate denial‑of‑service impact without privilege escalation. Based on the description, the likely attack vector is a malicious third‑party application that supplies crafted data to trigger the overflow. Attackers would need only to install or run such an app on an affected device.

Generated by OpenCVE AI on September 20, 2026 at 18:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the patched versions of iOS, iPadOS, or macOS that include the improved bounds checking.
  • Prevent installation of third‑party applications from untrusted sources until a patch is applied, or use device‑management policies to allow only approved apps.
  • Regularly monitor Apple Security Advisories and support pages for new patches or workarounds and apply them promptly.

Generated by OpenCVE AI on September 20, 2026 at 18:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Apple iOS and macOS Leading to Denial of Service

Wed, 16 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Buffer Overflow in Apple Operating Systems
Weaknesses CWE-119

Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Buffer Overflow in Apple Operating Systems
Weaknesses CWE-119

Tue, 15 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to cause a denial of service.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T15:25:41.612Z

Reserved: 2026-09-01T20:50:08.321Z

Link: CVE-2026-84489

cve-icon Vulnrichment

Updated: 2026-09-15T15:25:36.335Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:26.657

Modified: 2026-09-16T01:08:31.997

Link: CVE-2026-84489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:45:02Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')