Executive brief
The Accelerate Framework is a low-level performance library used by macOS applications for image processing and mathematical computations. An out-of-bounds memory write vulnerability allows an attacker to crash the system or potentially execute code with elevated privileges by providing a maliciously crafted image file.
Technical details
CVE-2026-84505 is an out-of-bounds write vulnerability in Apple's Accelerate Framework, addressed through improved bounds checking. The vulnerability is triggered when processing a maliciously crafted image, leading to memory corruption. An attacker can cause unexpected process termination or potentially execute arbitrary code. The attack requires local delivery of a malicious image file and does not require authentication. Patches are available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: patched: Fixes available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7
- 2026-09-14: disclosed