Junglewise Threat Intelligence

CVE-2026-84548: Apple macOS integer overflow in Accelerate Framework

CVE-2026-84548 · Severity: high · CVSS 7.1 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

The Accelerate Framework, a core macOS component used for processing images and data, contains an integer overflow vulnerability that can be triggered by a maliciously crafted document or image. Exploitation leads to an out-of-bounds memory read, which could allow an attacker to read sensitive data or crash the application.

Technical details

An integer overflow vulnerability exists in the Accelerate Framework's image processing code. The root cause is insufficient input validation when parsing maliciously crafted image files, leading to integer wraparound that causes out-of-bounds read operations. The vulnerability requires user interaction (opening a crafted document) and is reachable through network vectors if the document is delivered via email or web. Successful exploitation can result in information disclosure or denial of service. Apple addressed this with improved input validation in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7

References

Related threats