Junglewise Threat Intelligence

CVE-2026-84505: Apple macOS Accelerate Framework out-of-bounds write

CVE-2026-84505 · Severity: high · CVSS 7.8 · Published 2026-09-14

Technologies: Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

The Accelerate Framework is a low-level performance library used by macOS applications for image processing and mathematical computations. An out-of-bounds memory write vulnerability allows an attacker to crash the system or potentially execute code with elevated privileges by providing a maliciously crafted image file.

Technical details

CVE-2026-84505 is an out-of-bounds write vulnerability in Apple's Accelerate Framework, addressed through improved bounds checking. The vulnerability is triggered when processing a maliciously crafted image, leading to memory corruption. An attacker can cause unexpected process termination or potentially execute arbitrary code. The attack requires local delivery of a malicious image file and does not require authentication. Patches are available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: patched: Fixes available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7
  • 2026-09-14: disclosed

References

Related threats