Junglewise Threat Intelligence

CVE-2026-84538: Apple macOS denial-of-service via input validation

CVE-2026-84538 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

macOS is Apple's operating system for Mac computers. A remote attacker can exploit a denial-of-service vulnerability through improper input validation, potentially causing system hangs or crashes and disrupting user productivity. This affects multiple macOS versions and requires patching to maintain system stability.

Technical details

This vulnerability is a denial-of-service (DoS) issue triggered by improper input validation in an unspecified macOS component. A remote attacker can send a maliciously crafted input to cause unexpected process termination or system unresponsiveness. The attack vector is network-based with no authentication required, though user interaction may be involved. The fix addresses the root cause through improved input validation logic. The vulnerability is patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, all released on September 14, 2026.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats