Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D scene may lead to unexpected process termination.
Published: 2026-09-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

An out‑of‑bounds write was investigated in Apple’s graphics stack and addressed by improved bounds checking. This out‑of‑bounds write corresponds to CWE‑787, a buffer overflow vulnerability. Crafting a malicious 3‑D scene that exceeds expected limits can trigger the out‑of‑bounds write and cause the rendering process to terminate unexpectedly, leading to a denial of service that disrupts device usability but does not provide evidence of code execution or data leakage.

Affected Systems

Vulnerable Apple products include iOS and iPadOS, macOS (Golden Gate 27, Sequoia 15.8, Tahoe 26.7), tvOS 27, visionOS 27, and watchOS 27. The issue was fixed starting with iOS 26.7 / iPadOS 26.7, iOS 27 / iPadOS 27, and corresponding macOS, tvOS, visionOS, and watchOS releases.

Risk and Exploitability

Severity metrics are not high—CVSS 4.3 and EPSS < 1% indicate a low exploitation probability, and the vulnerability is not listed in CISA KEV catalog. The attack likely requires the attacker to supply or influence a 3‑D scene that is processed by the device, so user interaction or an active component is necessary. While the low EPSS score and absence of exploit data suggest low risk, the impact is a denial of service that can disrupt device usability.

Generated by OpenCVE AI on September 20, 2026 at 19:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest iOS, iPadOS, macOS, tvOS, visionOS, and watchOS updates (vulnerable versions listed) to apply the bounds‑checking fix for the buffer overflow (CWE‑787).
  • Disable or block third‑party or user‑supplied 3‑D scenes until the update is applied as a temporary measure, which mitigates the buffer overflow (CWE‑787) risk.
  • Notify stakeholders and schedule device updates during maintenance windows to ensure all devices receive the patch promptly.

Generated by OpenCVE AI on September 20, 2026 at 19:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Apple Graphics Stack Out‑of‑Bounds Write Can Cause Service Disruption

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Apple 3D Rendering Stack Leads to Crash
Weaknesses CWE-119

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Apple 3D Rendering Stack Leads to Crash
Weaknesses CWE-119

Tue, 15 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D scene may lead to unexpected process termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T16:56:17.691Z

Reserved: 2026-09-01T21:13:17.749Z

Link: CVE-2026-84526

cve-icon Vulnrichment

Updated: 2026-09-17T16:56:09.535Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:29.187

Modified: 2026-09-18T19:38:13.600

Link: CVE-2026-84526

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:00:04Z

Weaknesses