Junglewise Threat Intelligence

CVE-2026-84524: Apple iOS font parsing out-of-bounds read

CVE-2026-84524 · Severity: medium · CVSS 4.3 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS Golden Gate, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Apple's iOS and iPadOS operating systems contain a vulnerability in font file processing that can crash applications or cause unexpected terminations. An attacker can exploit this by distributing a maliciously crafted font file that, when processed by the system, triggers memory access violations. This could disrupt user experience and potentially be combined with other exploits to compromise device security.

Technical details

An out-of-bounds read vulnerability exists in the font parsing code across multiple Apple operating systems. The vulnerability occurs when processing a maliciously crafted font file, allowing an attacker to read memory beyond allocated buffer boundaries. Attack preconditions are minimal—the victim must process or encounter the malicious font (via an email attachment, web page, or system font installation). The immediate impact is denial of service through unexpected app termination; however, information disclosure of adjacent memory may be possible depending on exploitation. Patches are available in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.

Affected products

  • Apple iOS prior to 26.7 and 27
  • Apple iPadOS prior to 26.7 and 27
  • Apple macOS Golden Gate prior to 27
  • Apple macOS Sequoia prior to 15.8
  • Apple macOS Tahoe prior to 26.7
  • Apple tvOS prior to 27
  • Apple visionOS prior to 27
  • Apple watchOS prior to 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-84524 published; patches released for iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27

References

Related threats