Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or write kernel memory.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Kernel Memory Write Leading to Potential Code Execution
Action: Immediate Patch
AI Analysis

Impact

An out-of-bounds write in Apple operating systems was resolved with enhanced bounds checking. The issue allowed an application to write outside the intended buffer, potentially overwriting kernel memory and causing the system to terminate unexpectedly. This type of memory corruption could enable privilege escalation or arbitrary code execution, impacting confidentiality, integrity, and availability of the device.

Affected Systems

Affected releases include iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.

Risk and Exploitability

The vulnerability can be leveraged by any app that runs with sufficient privileges to trigger the write. Without a publicly available exploit, the exact exploitation path is unclear, but the potential for kernel memory alteration is high. No exploit has been cataloged in CISA KEV, and no EPSS score is available, which leaves the real-world exploitation likelihood uncertain; nevertheless, the high potential impact warrants prompt remediation.

Generated by OpenCVE AI on September 15, 2026 at 08:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest OS updates for all affected Apple platforms, which include the fix for iOS 27, iPadOS 27, macOS 27 or 15.8, macOS 26.7, tvOS 27, visionOS 27, and watchOS 27.
  • Restrict installation of untrusted applications and enforce device management policies to limit execution of privileged code.
  • Monitor for abnormal crashes or kernel panics and investigate any incidents promptly.

Generated by OpenCVE AI on September 15, 2026 at 08:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Leading to Kernel Memory Modification and System Crash in Apple Operating Systems
Weaknesses CWE-119

Tue, 15 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or write kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:51:02.122Z

Reserved: 2026-09-01T21:13:17.749Z

Link: CVE-2026-84523

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:28.863

Modified: 2026-09-14T21:17:28.863

Link: CVE-2026-84523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T09:00:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer