Junglewise Threat Intelligence

CVE-2026-84526: Apple Accelerate Framework out-of-bounds write in image processing

CVE-2026-84526 · Severity: medium · CVSS 4.3 · Published 2026-09-14

Technologies: Apple Tvos, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

The Accelerate Framework is a core Apple component used for image and signal processing across iOS, iPadOS, and macOS. A flaw in its bounds checking allows processing a malicious image to cause the application to crash unexpectedly, disrupting service availability and user productivity.

Technical details

An out-of-bounds write vulnerability exists in Apple's Accelerate Framework image processing code due to insufficient bounds checking. The vulnerability is triggered when processing a specially crafted malicious image, allowing an attacker to write data beyond allocated buffer boundaries. The attack requires only that the victim open or process a malicious image file—no special privileges or authentication are required. Successful exploitation results in unexpected process termination (denial of service); the advisory does not indicate remote code execution is possible. Apple has patched this issue in iOS 27, iPadOS 27, macOS Golden Gate 27, and other OS releases published September 14, 2026.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-84526 disclosed and patches released
  • 2026-09-14: patched: Fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27

References

Related threats