Description
An uninitialized memory issue was addressed with improved memory initialization. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may result in disclosure of process memory.
Published: 2026-09-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure via process memory leakage
Action: Apply patch
AI Analysis

Impact

The vulnerability arises from an uninitialized memory region that is used during image processing. When a crafted image is processed, data that was never properly initialized can be read from the process’s memory, releasing sensitive information. This is a classic instance of uninitialized variable usage (CWE-457). The CVSS score of 4.3 indicates a low severity rating.

Affected Systems

Apple devices running affected operating system releases: iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, which signifies a low probability of widespread exploitation. Based on the description, it is inferred that an attacker could deliver a malicious image—such as by prompting a user to open a file locally or via remote image handling—to trigger the memory disclosure. The resulting leak could expose data residing in the process’s address space. Although exploitation has not been publicly documented, the confidentiality impact recommends timely patching.

Generated by OpenCVE AI on September 20, 2026 at 19:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the device to iOS 26.7 or later, iPadOS 26.7 or later, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, or watchOS 27.
  • If an immediate OS update is not possible, avoid opening or processing images from unknown or untrusted sources until the patch is installed.
  • Ensure that all third‑party applications that handle image files are updated to the latest available versions to benefit from any additional security improvements.

Generated by OpenCVE AI on September 20, 2026 at 19:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Memory Disclosure Through Malicious Image Processing

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-457
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Memory in Image Processing Leading to Process Memory Disclosure
Weaknesses CWE-200
CWE-758

Tue, 15 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Memory in Image Processing Leading to Process Memory Disclosure
Weaknesses CWE-200
CWE-758

Tue, 15 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An uninitialized memory issue was addressed with improved memory initialization. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may result in disclosure of process memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T15:12:42.470Z

Reserved: 2026-09-01T21:13:17.754Z

Link: CVE-2026-84564

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:32.570

Modified: 2026-09-18T17:29:14.323

Link: CVE-2026-84564

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:00:04Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable