Description
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via System Crash
Action: Patch Update
AI Analysis

Impact

An integer overflow flaw was identified in Apple macOS. The vulnerability arises from insufficient input validation, allowing an attacker to provide a large numeric value that overflows an internal counter and results in the operating system terminating unexpectedly. This defect is tied to integer overflows (CWE‑190). The CVE description does not explicitly state that the overflow can result in arbitrary code execution or privilege escalation; however, it can cause a system crash, leading to a denial of service.

Affected Systems

Apple macOS versions older than macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are affected. The operating system has patched the flaw in those should check their installed macOS version and upgrade if it precedes these fixed releases.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% reflects a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The exploitation involves supplying a malicious input that overloads the integer handling routine; however, the description does not specify whether this can be performed locally or remotely, so the attack vector is uncertain.

Generated by OpenCVE AI on September 21, 2026 at 00:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update macOS to at least macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 to receive the input‑validation fix
  • Until the OS update is applied, avoid running applications or services that can generate large numeric inputs that might the vulnerability
  • Consult Apple’s support advisories to monitor for additional patches or guidance

Generated by OpenCVE AI on September 21, 2026 at 00:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title macOS Integer Overflow Causing Potential System Crash

Sun, 20 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in macOS That Can Crash the System
Weaknesses CWE-680

Wed, 16 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in macOS That Can Crash the System
Weaknesses CWE-680

Tue, 15 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T17:43:27.163Z

Reserved: 2026-09-01T21:13:17.749Z

Link: CVE-2026-84517

cve-icon Vulnrichment

Updated: 2026-09-15T17:43:22.512Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:28.257

Modified: 2026-09-16T18:01:45.790

Link: CVE-2026-84517

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:00:08Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound