Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. A sandboxed process may be able to circumvent sandbox restrictions.
Published: 2026-09-14
Score: 5.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sandbox restriction circumvention
Action: Patch Now
AI Analysis

Impact

The vulnerability involves an out‑of‑bounds write in several sandboxed processes, allowing a process to write memory beyond the intended bounds. This flaw can potentially enable a sandboxed application to bypass the sandbox restrictions that are meant to limit its access to system resources, thereby exposing the integrity and stability of the affected system to risk.

Affected Systems

Affected Apple operating systems include iOS, iPadOS, macOS (Golden Gate, Sequoia, Tahoe), visionOS, and watchOS. Versions before iOS 26.7, iPadOS 26.7, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, and watchOS 27 are vulnerable and should be upgraded to the patched releases.

Risk and Exploitability

The CVSS score of 5.2 indicates moderate severity, while the EPSS score is <1% and the vulnerability is not listed in the KEV catalog, suggesting that widespread exploitation is unlikely. Based on the description, it is inferred that an attacker would need to exploit a local sandboxed process that triggers the memory overwrite in order to circumvent sandbox restrictions. The potential impact is limited to the capabilities of the sandboxed process; explicit elevation of privileges beyond the sandbox is not confirmed by the available data.

Generated by OpenCVE AI on September 17, 2026 at 20:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade all Apple iOS, iPadOS, macOS, visionOS, and watchOS devices to the latest versions that contain the bounds‑checking fix
  • Configure devices to automatically download and install future software updates as soon as they are released
  • Limit the use of untrusted sandboxed applications until a patched OS is available

Generated by OpenCVE AI on September 17, 2026 at 20:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Apple OS Sandbox Escalation via Out-of-Bounds Write

Wed, 16 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title Sandbox Escalation via Out‑of‑Bounds Write in Apple Operating Systems

Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 15 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Sandbox Escalation via Out‑of‑Bounds Write in Apple Operating Systems

Tue, 15 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 5.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. A sandboxed process may be able to circumvent sandbox restrictions.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Visionos Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T22:50:45.086Z

Reserved: 2026-09-08T16:43:41.871Z

Link: CVE-2026-86876

cve-icon Vulnrichment

Updated: 2026-09-14T22:50:38.948Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:38.687

Modified: 2026-09-15T17:28:22.230

Link: CVE-2026-86876

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:00:16Z

Weaknesses