Junglewise Threat Intelligence

CVE-2026-84532: Apple iOS and iPadOS out-of-bounds read in Accelerate Framework

CVE-2026-84532 · Severity: medium · CVSS 5.4 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS Golden Gate, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

iOS and iPadOS include a framework for image processing and mathematical calculations used by many apps. A maliciously crafted image file can trigger an out-of-bounds memory read, causing the affected app to crash unexpectedly or leak sensitive data from the device's memory. Apple addressed this issue with improved input validation in iOS 27 and iPadOS 27, released September 14, 2026.

Technical details

An out-of-bounds read vulnerability exists in Apple's Accelerate Framework, which processes images and performs mathematical operations. The vulnerability is triggered when the framework processes a maliciously crafted image file with invalid bounds, allowing reading of memory outside the allocated buffer. The attack vector is local and requires a user to open a crafted image file, but no special privileges are required. A successful exploit can cause unexpected process termination (denial of service) or disclose sensitive process memory contents to an attacker. The fix was addressed with improved input validation in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, and visionOS 27.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-84532 published in NVD
  • 2026-09-14: patched: Fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, and other versions

References

Related threats