Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. Processing maliciously crafted NTLM input may lead to unexpected app termination.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

An out‑of‑bounds write flaw was discovered in the NTLM input handling code on Apple platforms. The flaw is triggered when the software processes specially crafted NTLM packets that bypass existing bounds checks, leading to memory corruption outside the intended buffer. Because the code fails to validate the size of the input correctly, a malformed packet can corrupt memory and cause the application that processes the NTLM data to terminate unexpectedly, resulting in a denial‑of‑service condition.

Affected Systems

The vulnerability affects Apple devices running iOS, iPadOS, and macOS Golden Gate that have not been updated to version 27. Apple’s official advisory states that the issue was addressed with improved bounds checking in iOS 27, iPadOS 27 and macOS Golden Gate 27. The affected products are Apple iOS, Apple iPadOS and Apple macOS Golden Gate.

Risk and Exploitability

The CVE entry does not provide a CVSS score or EPSS value, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be an authenticated or unauthenticated NTLM authentication request sent to the device, which can be local or remote. Because the flaw only causes application termination, there is no evidence of privilege escalation or data exfiltration, but it can disrupt user experience and availability if exploited repeatedly. The absence of a published CVSS metric makes it difficult to quantify the severity, but the observed effect of a crash suggests a high impact on availability for the affected application.

Generated by OpenCVE AI on September 15, 2026 at 10:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Apple devices to iOS 27, iPadOS 27 or macOS Golden Gate 27 to receive the bounds‑checking fix.
  • If an OS upgrade is not immediately feasible, block NTLM authentication traffic to the devices using network filtering or firewall rules to prevent malicious packets from reaching the vulnerable code.
  • Enable crash reporting for the affected applications so that unexpected terminations can be logged and analyzed for further investigation.

Generated by OpenCVE AI on September 15, 2026 at 10:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title NTLM Input Out‑of‑Bounds Write Leading to App Crash
Weaknesses CWE-125

Tue, 15 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. Processing maliciously crafted NTLM input may lead to unexpected app termination.
References

Subscriptions

Apple Ios And Ipados Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:48:50.746Z

Reserved: 2026-09-01T21:13:17.750Z

Link: CVE-2026-84531

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:29.523

Modified: 2026-09-14T21:17:29.523

Link: CVE-2026-84531

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T10:30:12Z

Weaknesses