Description
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Opening a maliciously crafted file may cause unexpected process termination or disclose process memory.
Published: 2026-09-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Disclosure or Denial of Service
Action: Apply Patch
AI Analysis

Impact

An out-of-bounds read was identified in the file handling logic on Apple platforms. When a maliciously crafted file is opened, the operating system may read beyond the intended data boundaries, leading to either unexpected process termination or the disclosure of data residing in process memory. This flaw can compromise confidentiality and availability.

Affected Systems

Apple iOS and iPadOS releases prior to 26.7, macOS Golden Gate and earlier releases before 27, macOS Sequoia releases before 15.8, macOS Tahoe releases before 26.7, tvOS releases before 27, and visionOS releases before 27 are affected by the issue.

Risk and Exploitability

The vulnerability can be leveraged simply by opening a crafted file, making it available to users who can trigger it. An EPSS score of < 1% indicates a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. The CVSS score of 5.4 classifies the issue as moderate severity, but the potential impact of process memory disclosure and a system crash still poses a significant threat to affected devices when untrusted files are accessed.

Generated by OpenCVE AI on September 20, 2026 at 19:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the affected Apple operating systems to iOS 26.7, 27 or later, iPadOS 26.7, 27 or later, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7 or later, tvOS 27, or visionOS 27, as applicable. This update corrects the input validation in file handling that caused the out-of-bounds read.
  • Restrict access to untrusted documents by using sandboxed or read-only containers, and review file handling policies to ensure that only expected file formats are opened without additional validation.
  • Monitor for application crashes or abnormal memory behavior after accessing files, and apply vendor security advisories promptly while waiting for future updates to further harden the file parsing logic.

Generated by OpenCVE AI on September 20, 2026 at 19:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Apple File Handling Allows Process Termination or Memory Disclosure

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in File Handling Causes Termination or Memory Disclosure on Apple Platforms
Weaknesses CWE-20

Tue, 15 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in File Handling Causes Termination or Memory Disclosure on Apple Platforms
Weaknesses CWE-20

Tue, 15 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Opening a maliciously crafted file may cause unexpected process termination or disclose process memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T16:17:50.621Z

Reserved: 2026-09-01T21:13:17.750Z

Link: CVE-2026-84532

cve-icon Vulnrichment

Updated: 2026-09-17T16:17:43.689Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:29.630

Modified: 2026-09-18T19:37:57.970

Link: CVE-2026-84532

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:45:02Z

Weaknesses