Junglewise Threat Intelligence

CVE-2026-84523: Apple APFS out-of-bounds write

CVE-2026-84523 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS Golden Gate, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

APFS is the file system Apple uses to store and manage data on iOS, iPadOS, and macOS devices. A flaw in APFS allows a malicious app to write data to protected kernel memory areas, potentially crashing the system or enabling attackers to execute unauthorized code with privileged access. This could result in complete device compromise.

Technical details

CVE-2026-84523 is an out-of-bounds write vulnerability in APFS (Apple File System) affecting iOS, iPadOS, and macOS. The vulnerability results from insufficient bounds checking in the file system code, allowing an app to write beyond allocated memory regions. An attacker with local code execution (via a malicious app) can trigger this flaw to write to kernel memory, potentially causing a denial of service (unexpected system termination) or enabling privilege escalation. The vulnerability requires local app execution; network-based exploitation is not possible. Apple patched this issue across iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.

Affected products

  • Apple iOS before 26.7, before 27
  • Apple iPadOS before 26.7, before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-84523 published and patches released
  • 2026-09-14: patched: Fixed in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27

References

Related threats