Description
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption and system crash via race condition
Action: Patch
AI Analysis

Impact

A timing race condition within the operating‑system core can allow a malicious application to trigger unexpected system termination or corrupt kernel memory. The flaw stems from improper synchronization, which may lead to loss of data, compromise of system integrity, and denial of service by forcing the device to reboot.

Affected Systems

Apple devices running iOS 26.7 or 27, iPadOS 26.7 or 27, macOS Golden Gate 27, Sequoia 15.8, and Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 are affected. The vulnerability has been fixed in all subsequent OS releases.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score of <1% suggests a very low probability of exploitation at this time. The flaw is not listed in CISA’s KEV catalog. Attackers would most likely trigger the race condition by installing a malicious or buggy application with elevated privileges; this inference is drawn from the description that an app may cause the failure. Because the vulnerability affects kernel memory, a successful exploit could lead to denial of service or potential privilege escalation if the attacker also gains code execution, though such escalation is not explicitly documented.

Generated by OpenCVE AI on September 20, 2026 at 21:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest macOS, iOS, iPadOS, tvOS, visionOS, and watchOS updates—iOS 26.7 or later, iPadOS 26.7 or later, macOS Sequoia 15.8 or later, macOS Golden Gate 27 or later, macOS Tahoe 26.7 or later, tvOS 27 or later, visionOS 27 or later, and watchOS 27 or later.
  • Ensure all third‑party applications are updated to the latest compatible versions or remove them temporarily, as a poorly written app could trigger the race condition before the OS update is applied.
  • Continuously monitor Apple security advisories and apply any interim patches released after the initial rollout to keep protection current.

Generated by OpenCVE AI on September 20, 2026 at 21:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Race Condition Leading to Kernel Memory Corruption and System Crash

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Race Condition Leading to Kernel Memory Corruption and System Crash
Weaknesses CWE-362

Tue, 15 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Race Condition Leading to Kernel Memory Corruption and System Crash
Weaknesses CWE-362

Tue, 15 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T15:39:21.690Z

Reserved: 2026-09-01T21:13:17.748Z

Link: CVE-2026-84507

cve-icon Vulnrichment

Updated: 2026-09-17T15:39:11.552Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:27.300

Modified: 2026-09-18T19:40:03.317

Link: CVE-2026-84507

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:00:09Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')