Executive brief
Apple macOS is the operating system that powers Mac computers. A network-reachable integer overflow vulnerability could allow an attacker with access to the local network to cause the system to crash or stop responding, disrupting user work and productivity. This affects multiple recent versions of macOS.
Technical details
An integer overflow vulnerability was identified in macOS network processing code. The flaw is triggered by maliciously crafted network input that is not properly validated before integer calculations. An attacker positioned on the same network segment can trigger a denial-of-service condition by sending specially crafted packets. The vulnerability requires adjacent network access but does not require authentication. Apple addressed the issue with improved input validation in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed: CVE-2026-84554 published; patches released for macOS Golden Gate 27, Sequoia 15.8, and Tahoe 26.7