Junglewise Threat Intelligence

CVE-2026-84521: Apple iOS and iPadOS use after free in memory management

CVE-2026-84521 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

iOS and iPadOS contain a use-after-free memory vulnerability that could allow an app to cause unexpected system termination. This issue affects iPhone and iPad devices and impacts system stability, potentially disrupting user operations and device functionality.

Technical details

A use-after-free vulnerability in iOS and iPadOS memory management allows an app to reference freed memory, leading to unexpected process termination. The vulnerability is triggered when an application accesses memory that has already been deallocated. An attacker can craft a malicious app that exploits this condition to cause a denial of service through system crashes. The issue is addressed in iOS 26.7, iOS 27, iPadOS 26.7, and iPadOS 27 through improved memory management controls.

Affected products

  • Apple iOS before 26.7, before 27
  • Apple iPadOS before 26.7, before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple visionOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-84521 published
  • 2026-09-14: patched: Patches released in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27

References

Related threats