Junglewise Threat Intelligence

CVE-2026-84511: Apple Accelerate Framework out-of-bounds write in image processing

CVE-2026-84511 · Severity: high · CVSS 7.8 · Published 2026-09-14

Technologies: Apple Tvos, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

The Accelerate Framework is a low-level library used across Apple's platforms to optimize image and signal processing tasks. A flaw in the framework's image handling allows attackers to cause apps or the system to crash unexpectedly by sending a maliciously crafted image file, disrupting service availability on affected devices.

Technical details

This is an out-of-bounds write vulnerability in Apple's Accelerate Framework image processing code, caused by insufficient bounds checking when handling crafted image data. The attack requires a user or application to open/process a maliciously crafted image file; no special permissions or authentication is needed beyond the ability to deliver a malicious image. Exploitation leads to unexpected process termination (denial of service). The vulnerability affects iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Patches are available in these released versions.

Affected products

  • Apple iOS 27 and later
  • Apple iPadOS 27 and later
  • Apple macOS Golden Gate 27 and later
  • Apple macOS Sequoia 15.8 and later
  • Apple macOS Tahoe 26.7 and later
  • Apple tvOS 27 and later
  • Apple visionOS 27 and later
  • Apple watchOS 27 and later

Timeline

  • 2026-09-14: disclosed: CVE-2026-84511 disclosed; iOS 27, iPadOS 27, macOS Golden Gate 27 patched
  • 2026-09-14: patched: Patches released for iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27

References

Related threats