Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption.
Published: 2026-09-14
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential memory corruption leading to arbitrary code execution or crash
Action: Immediate Patch
AI Analysis

Impact

An out-of-bounds write flaw in Apple's 3D model processing code permits a malicious model to corrupt memory locations. The vulnerability arises from insufficient bounds verification, which may allow an attacker to overwrite adjacent memory structures. If exploited, an attacker could potentially execute arbitrary code or crash the application, resulting in loss of data or functionality.

Affected Systems

Affected products include Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Versions prior to iOS OS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 remain vulnerable. System administrators should verify the operating system and upgrade if still running an older version.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity, while the EPSS score of <1% suggests a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires delivering a maliciously crafted 3D model to the device for processing by the native viewer or a web integration. The likely attack vector is local or remote, depending on whether sourced 3D content. Given the memory corruption risk, an attacker could achieve arbitrary code execution or a denial of service.

Generated by OpenCVE AI on September 20, 2026 at 18:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Apple OS update that includes the fix (iOS 27, iPadOS 27, macOS Sequoia 15.8, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27).
  • Disable or restrict the native 3D viewer on devices that do not need it, and restrict any web integrations that may process 3D models until they are patched.
  • Implement sandboxing and input validation for any remaining 3D model handling to reject malformed files automatically.

Generated by OpenCVE AI on September 20, 2026 at 18:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption via Malicious 3D Model in Apple 3D Processing

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption via Malicious 3D Model in Apple 3D Processing
Weaknesses CWE-119

Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Write Exploitable via Malicious 3D Models in Apple 3D Viewers

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Write Exploitable via Malicious 3D Models in Apple 3D Viewers
Weaknesses CWE-119

Tue, 15 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T03:56:23.631Z

Reserved: 2026-09-01T21:13:23.285Z

Link: CVE-2026-84611

cve-icon Vulnrichment

Updated: 2026-09-15T14:36:09.140Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:36.240

Modified: 2026-09-16T18:25:52.467

Link: CVE-2026-84611

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:00:04Z

Weaknesses