Junglewise Threat Intelligence

CVE-2026-84510: Apple iOS, iPadOS, and macOS heap buffer overflow in AppleDouble

CVE-2026-84510 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apple iPadOS, Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

A heap buffer overflow vulnerability affects Apple's file handling when mounting disk images or volumes containing maliciously crafted files. An attacker can exploit this by providing a specially prepared volume, causing the system to unexpectedly terminate or potentially execute arbitrary code. This could be leveraged to crash devices or gain unauthorized access to systems.

Technical details

A heap buffer overflow in AppleDouble, Apple's file system component responsible for handling dual-fork files and disk image mounting, was addressed with improved bounds checking. The vulnerability is triggered when mounting a maliciously crafted volume or disk image with specially constructed files. An attacker with the ability to provide a crafted storage medium or file system image can cause a denial of service through unexpected system termination. The attack requires user interaction (mounting a volume) but no authentication. Patches are available in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple iOS prior to 26.7 and 27
  • Apple iPadOS prior to 26.7 and 27
  • Apple macOS Golden Gate prior to 27
  • Apple macOS Sequoia prior to 15.8
  • Apple macOS Tahoe prior to 26.7

Timeline

  • 2026-09-14: disclosed: CVE-2026-84510 publicly disclosed
  • 2026-09-14: patched: Patches released in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7

References

Related threats