Junglewise Threat Intelligence

CVE-2026-84552: Apple iOS and macOS memory handling denial of service

CVE-2026-84552 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A memory handling flaw in Apple's iOS, iPadOS, and macOS operating systems could allow an app to cause unexpected system termination, disrupting user access to their device. This vulnerability affects iPhones, iPads, and Mac computers, potentially forcing users to restart their devices and lose unsaved work.

Technical details

The vulnerability is a memory handling issue in iOS, iPadOS, and macOS that can be triggered by an application running on the affected device. An attacker with the ability to run an app on the target device can craft specific conditions to cause an out-of-bounds memory access or similar memory management error, resulting in unexpected process or system termination (denial of service). The issue requires local execution of code within the app sandbox, so it cannot be exploited remotely. Apple addressed the vulnerability by implementing improved memory handling and bounds checking across affected components. The issue is fixed in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple iOS before 26.7 and 27
  • Apple iPadOS before 26.7 and 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed: CVE-2026-84552 published; patches released for iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7

References

Related threats