Description
A race condition was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A sandboxed app may be able to execute arbitrary code with kernel privileges.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Kernel Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

A race condition was identified in Apple operating systems that may allow a sandboxed application to execute arbitrary code with kernel privileges. The security advisory notes that the issue has been mitigated by improving state management, but does not provide further detail on the specific execution path. The potential impact is that an attacker could gain kernel‑level access, compromising confidentiality, integrity, and availability of the device.

Affected Systems

Apple iOS 26.7 through 27, iPadOS 26.7 through 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 are all affected. The issue has been addressed in these releases by enhancing state handling to prevent the race condition.

Risk and Exploitability

Because the flaw can enable kernel‑level code execution, the potential impact is severe. The EPSS score is unavailable and the vulnerability has not been listed in the CISA KEV catalog, indicating limited evidence of exploitation in the wild. Nonetheless, the likely attack vector involves a malicious sandboxed application; any user who installs such an app from outside the trusted App Store could be at risk.

Generated by OpenCVE AI on September 15, 2026 at 09:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to the latest available OS release that contains the race‑condition fix (iOS 27, iPadOS 27, macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.7, tvOS 27, visionOS 27, or watchOS 27).
  • Enable automatic system updates to ensure the device receives the security patch promptly.
  • Only install applications from the official Apple App Store or other vetted sources to reduce the likelihood that a malicious sandboxed application is installed.

Generated by OpenCVE AI on September 15, 2026 at 09:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title Race Condition in Apple OS Allows Kernel Privilege Escalation via Sandboxed App
Weaknesses CWE-362

Tue, 15 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A sandboxed app may be able to execute arbitrary code with kernel privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:51:27.510Z

Reserved: 2026-09-01T21:13:23.285Z

Link: CVE-2026-84607

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:36.033

Modified: 2026-09-14T21:17:36.033

Link: CVE-2026-84607

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T09:15:18Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')