Description
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to cause a denial-of-service.
Published: 2026-09-14
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The flaw is an integer overflow that occurs when unvalidated input causes a wraparound of an internal counter, allowing an attacker to trigger a crash in a privileged component and thereby cause a denial of service. The vendor addressed the issue with stricter input validation and the patch is deployed in macOS Golden Gate 27, Sequoia 15.8, and Tahoe exposed to this vulnerability.

Affected Systems

Apple macOS installations running releases older than Golden Gate 27, Sequoia 15.8, or Tahoe 26.7 are affected. Users on these versions continue to be at risk because the integer overflow remains unpatched.

Risk and Exploitability

The CVSS score of 5.9 indicates Medium severity, reflecting the attack vector, privileges, and scope. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, implying requires privileged network access to deliver the overflow payload and once exploited it causes service disruption, leading to loss of availability for the affected system.

Generated by OpenCVE AI on September 20, 2026 at 19:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest macOS updates that include the integer overflow fix (Golden Gate 27, Sequoia 15.8, or Tahoe 26.7).
  • Temporarily block or restrict network services that accept privileged input until the patch is applied.
  • Continuously monitor system logs for repeated denial‑of‑service attempts and investigate any abnormal patterns.

Generated by OpenCVE AI on September 20, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Privileged Integer Overflow in macOS

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 16 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Privileged Integer Overflow in macOS

Wed, 16 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow Leading to Denial of Service in macOS
Weaknesses CWE-680

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow Leading to Denial of Service in macOS
Weaknesses CWE-680

Tue, 15 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to cause a denial-of-service.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T15:01:47.531Z

Reserved: 2026-09-01T21:13:17.752Z

Link: CVE-2026-84554

cve-icon Vulnrichment

Updated: 2026-09-15T15:01:39.265Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:31.557

Modified: 2026-09-16T17:11:31.090

Link: CVE-2026-84554

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:30:04Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound