Description
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. Extracting a maliciously crafted archive may allow an attacker to write arbitrary files.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Write
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from insufficient validation of file paths when extracting archives (CWE-22). A malicious archive can include paths that escape the intended extraction directory, allowing the attacker to write files to arbitrary locations. This could overwrite system binaries, configuration files, or user data, potentially leading to privilege escalation, persistence, or denial of service.

Affected Systems

Affected Apple operating systems include iOS and iPadOS versions prior to 26.7 and 27, macOS Golden Gate prior to 27, macOS Sequoia before 15.8, macOS Tahoe before 26.7, and visionOS before 27. The issue is fixed in the versions listed above.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity level. The EPSS score of < 1% shows a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via extraction of a malicious archive, which may be delivered by email attachments, downloaded files, or malicious apps. Successful exploitation would require that the archive is processed by a system component with sufficient privileges.

Generated by OpenCVE AI on September 20, 2026 at 18:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest software updates: install iOS 26.7+ or later, iPadOS 26.7+ or later, macOS Golden Gate 27+ or later, macOS Sequoia 15.8+ or later, macOS Tahoe 26.7+ or later, and visionOS 27+ or later.
  • If an immediate update is infeasible, restrict or disable extraction of untrusted archives on the device—disable archive extraction features in applications, enforce stricter sandbox boundaries, or require explicit user permission for extraction.
  • Monitor device logs for unexpected file writes and enable file‑integrity monitoring; keep applying any additional Apple security updates as they become available.

Generated by OpenCVE AI on September 20, 2026 at 18:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Arbitrary File Write via Malicious Archive Extraction

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Arbitrary File Write via Malicious Archive Extraction

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Path Handling Vulnerability Enabling Arbitrary File Write

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title Path Handling Vulnerability Enabling Arbitrary File Write
Weaknesses CWE-22

Tue, 15 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. Extracting a maliciously crafted archive may allow an attacker to write arbitrary files.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T19:25:48.116Z

Reserved: 2026-09-01T21:13:17.750Z

Link: CVE-2026-84534

cve-icon Vulnrichment

Updated: 2026-09-15T19:23:55.745Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:29.850

Modified: 2026-09-16T14:13:12.300

Link: CVE-2026-84534

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:45:02Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')