Description
A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Golden Gate 27. A local attacker may be able to cause unexpected system termination or corrupt kernel memory.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption or system termination
Action: Apply Update
AI Analysis

Impact

A buffer overflow in the macOS kernel arises from insufficient size validation, which can lead to unexpected system termination or kernel memory corruption. The vulnerability is a classic buffer overflow where boundary checks around a memory buffer are missing. Based on the description, it is inferred that an attacker with local access could trigger this overflow to destabilize the system.

Affected Systems

Apple macOS systems of versions earlier than macOS Golden Gate 27 are affected; the fix is included in macOS Golden Gate 27 and later releases.

Risk and Exploitability

The attack vector is likely local; a user with local privileges could exploit the overflow. The EPSS score is reported as less than 1%, indicating a low but non‑zero probability of exploitation. The CVSS score of 9.8 indicates a critical severity. The vulnerability is not listed in the CISA KeV catalog and is fixed in macOS Golden Gate 27 or later releases.

Generated by OpenCVE AI on September 20, 2026 at 21:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the macOS update that includes the buffer overflow fix (macOS Golden Gate 27 or later).
  • Reboot the system after applying the update to ensure the patched kernel is running.
  • Restrict local user privileges until the update is applied to reduce the attack surface.

Generated by OpenCVE AI on September 20, 2026 at 21:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 20 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Local Buffer Overflow Causing Kernel Corruption and System Termination in macOS

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Kernel buffer overflow leads to system termination or memory corruption
Weaknesses CWE-119
CWE-120

Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Kernel buffer overflow leads to system termination or memory corruption
Weaknesses CWE-119
CWE-120

Tue, 15 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Golden Gate 27. A local attacker may be able to cause unexpected system termination or corrupt kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T14:35:45.611Z

Reserved: 2026-09-01T21:13:17.749Z

Link: CVE-2026-84520

cve-icon Vulnrichment

Updated: 2026-09-16T14:35:34.965Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:28.550

Modified: 2026-09-16T17:14:37.690

Link: CVE-2026-84520

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:45:04Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')