Executive brief
Apple's Neural Engine, a processor component used for machine learning tasks on iPhones, iPads, and Macs, contains an integer overflow vulnerability. A malicious file processed by the Neural Engine could be exploited to read sensitive data from device memory, potentially exposing personal information, passwords, or other confidential content stored by running applications.
Technical details
An integer overflow vulnerability was identified in the Apple Neural Engine component, addressed through improved input validation. The vulnerability is triggered when processing a maliciously crafted file, allowing an attacker to cause an integer wraparound condition. This leads to disclosure of process memory, enabling information disclosure attacks. The issue affects iOS 26.7 and earlier, iOS 27 and earlier (prior to patch), iPadOS 26.7 and earlier, iPadOS 27 and earlier (prior to patch), macOS Golden Gate 27 and earlier, macOS Sequoia 15.7 and earlier, and other Apple platforms. The attack likely requires local access or the ability to cause the Neural Engine to process untrusted content. Patches are available in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.
Affected products
- Apple iOS 26.7 and earlier
- Apple iPadOS 26.7 and earlier
- Apple macOS Golden Gate 27 and earlier
- Apple macOS Sequoia 15.7 and earlier
- Apple macOS Tahoe 26.7 and earlier
- Apple tvOS 27 and earlier
- Apple visionOS 27 and earlier
- Apple watchOS 27 and earlier
Timeline
- 2026-09-14: disclosed: CVE-2026-84487 published and patches released
- 2026-09-14: patched: Fixes released in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27