Description
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Opening a maliciously crafted file may lead to unexpected process termination.
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via buffer overflow leading to process termination
Action: Immediate Patch
AI Analysis

Impact

A buffer overflow was caused by improper size validation in Apple OS components. Opening a specially crafted file can trigger the flaw, causing the targeted process to crash unexpectedly. The crash does not directly expose code execution, but it can destabilize the system and disrupt services that rely on the affected process.

Affected Systems

The vulnerability affects Apple devices running iOS earlier than version 26.7 or 27, iPadOS earlier than 26.7 or 27, macOS Golden Gate earlier than 27, macOS Sequoia earlier than 15.8, macOS Tahoe earlier than 26.7, tvOS earlier than 27, and visionOS earlier than 27. The flaw is fixed in the listed advisory versions; all earlier releases remain vulnerable until an update is applied.

Risk and Exploitability

It is not listed in CISA KEV and has an EPSS score below 1%, indicating a very low probability of exploitation. The CVSS score is 7.8, indicating high severity. The vulnerability remains local or user‑initiated, as it requires opening a maliciously crafted file. The impact is a denial of service via unexpected process termination, which can disrupt affected services but does not provide arbitrary code execution or privilege escalation.

Generated by OpenCVE AI on September 20, 2026 at 20:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest security updates for iOS, iPadOS, macOS, tvOS, and visionOS that include the patch for this buffer overflow, which are iOS 26.7 or later, iOS 27 or later, iPadOS 26.7 or later, iPadOS 27 or later, macOS Golden Gate 27 or later, macOS Sequoia 15.8 or later, macOS Tahoe 26.7 or later, tvOS 27 or later, and visionOS 27 or later.
  • If an immediate update is unavailable, isolate or disable the affected application or service that could process malicious files to reduce the attack surface.
  • Implement file‑type whitelisting or sandboxing on all Apple devices to prevent the execution of potentially dangerous files until the vulnerability is fully patched.

Generated by OpenCVE AI on September 20, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Apple OS Components Allows Process Termination via Malicious Files

Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Apple OS Components Allows Process Crash
Weaknesses CWE-119
CWE-120

Tue, 15 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Apple OS Components Allows Process Crash
Weaknesses CWE-119
CWE-120

Tue, 15 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Opening a maliciously crafted file may lead to unexpected process termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T15:16:47.189Z

Reserved: 2026-09-01T20:50:08.322Z

Link: CVE-2026-84497

cve-icon Vulnrichment

Updated: 2026-09-16T15:16:16.603Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:26.970

Modified: 2026-09-16T18:26:42.430

Link: CVE-2026-84497

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:30:05Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')