Description
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted font may result in the disclosure of process memory.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Disclosure
Action: Update OS
AI Analysis

Impact

An out-of-bounds read vulnerability (CWE-125) is triggered when a maliciously crafted font is processed by the operating system. This flaw allows an attacker to read portions of a process’s memory that should be inaccessible, potentially leaking sensitive data such as passwords, cryptographic keys, or other confidential information. The weakness stems from insufficient bounds checking during font parsing, which can lead to accidental disclosure of memory contents.

Affected Systems

Apple devices running iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, or watchOS 27 are not affected. These versions contain the patch that tightens input validation to prevent the out-of-bounds read. All earlier releases of each platform remain vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, while an EPSS score of less than 1 % signals a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further reducing the likelihood of widespread attacks. The most likely attack path involves delivering a malicious font through a compromised or malicious application, or via a user-initiated font installation. Exploitation would grant an attacker read access to the memory of the process rendering the font, compromising confidentiality for the affected user but not enabling arbitrary code execution. The limited scope and low exploitation likelihood suggest monitoring and prompt patching rather than immediate emergency measures.

Generated by OpenCVE AI on September 20, 2026 at 19:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade all Apple devices to the latest operating system releases that include the patch for iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27.
  • Restrict the installation of custom fonts from untrusted sources; disable automatic font downloads or enforce a policy that permits only fonts from verified publishers.
  • Configure device management or security settings to grant applications that render fonts the minimum privileges required, reducing the impact of an out-of-bounds read if the vulnerability were exploited.

Generated by OpenCVE AI on September 20, 2026 at 19:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read via Malicious Font Causing Memory Disclosure

Wed, 16 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read via Malicious Font Causing Memory Disclosure

Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted font may result in the disclosure of process memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T14:48:07.880Z

Reserved: 2026-09-01T21:13:17.758Z

Link: CVE-2026-84597

cve-icon Vulnrichment

Updated: 2026-09-15T14:47:59.205Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:35.297

Modified: 2026-09-16T01:06:12.090

Link: CVE-2026-84597

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:15:03Z

Weaknesses