Description
A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted volume may lead to unexpected system termination.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (System Termination)
Action: Apply Patch
AI Analysis

Impact

A heap buffer overflow in Apple’s iOS, iPadOS, and macOS operating systems occurs during the bounds‑checked processing of volume mount operations. The flaw allows malicious data from a volume to overflow a heap buffer, corrupting memory and causing the system to crash unexpectedly, resulting in an unsolicited system termination that takes down the kernel or related processes.

Affected Systems

The vulnerability affects Apple iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Devices running any of these operating system releases are susceptible when a malicious or tampered volume is mounted.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1 % suggests a low probability of widespread exploitation at the time this analysis was performed. The vulnerability is not listed in CISA’s KEV catalog. Attacking requires access to a volume that can be mounted locally; no publicly described exploit code is present in the available data, so remediation is strongly recommended.

Generated by OpenCVE AI on September 20, 2026 at 20:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest available iOS, iPadOS, or macOS release that includes the fix (iOS 26.7/27, iPadOS 26.7/27, macOS Golden Gate 27, Sequoia 15.8, or Tahoe 26.7).
  • Avoid mounting untrusted or unknown volumes until the patch is applied or the device is upgraded.
  • On macOS, disable automatic mounting of external volumes or restrict mount operations to trusted sources via System Preferences → Security & Privacy or by using the ‘diskutil’ command; apply these restrictions until the patch is installed.

Generated by OpenCVE AI on September 20, 2026 at 20:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Volume Mount Operations Leading to System Termination

Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Apple iOS, iPadOS, and macOS Leading to System Termination
Weaknesses CWE-120

Tue, 15 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Apple iOS, iPadOS, and macOS Leading to System Termination
Weaknesses CWE-120

Tue, 15 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted volume may lead to unexpected system termination.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T14:47:40.883Z

Reserved: 2026-09-01T21:13:17.748Z

Link: CVE-2026-84510

cve-icon Vulnrichment

Updated: 2026-09-17T14:47:33.579Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:27.510

Modified: 2026-09-18T16:36:46.707

Link: CVE-2026-84510

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:30:05Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow