Junglewise Threat Intelligence

CVE-2026-84506: Apple macOS kernel use-after-free in memory management

CVE-2026-84506 · Severity: high · CVSS 7.8 · Published 2026-09-14

Technologies: Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

macOS is the operating system that powers Apple's computers. A use-after-free vulnerability in the kernel could allow a malicious application to execute arbitrary code with the highest system privileges, potentially compromising the entire computer and any sensitive data stored on it. This type of vulnerability is particularly serious because it affects the core operating system that manages all running applications.

Technical details

The vulnerability is a use-after-free issue in the macOS kernel memory management subsystem, allowing an application to reference and manipulate memory that has been freed. The attack requires local execution (the attacker must run code on the system), but no user interaction or elevated privileges are required as a prerequisite—the exploit itself elevates to kernel privileges. An attacker can leverage this flaw to achieve arbitrary code execution with kernel-level privileges, effectively taking full control of the affected system. The issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 through improved memory management.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed: CVE-2026-84506 published; patched in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7

References

Related threats