Executive brief
macOS Golden Gate 27 contains a double free vulnerability in memory management that could allow an app to cause unexpected system termination. While this does not enable data theft or privilege escalation, it can disrupt system stability and user productivity by crashing the operating system.
Technical details
A double free vulnerability occurs when memory is freed twice, corrupting the heap and potentially allowing arbitrary code execution or denial of service. In this case, the issue was addressed through improved memory management in macOS Golden Gate 27. The vulnerability allows a local app to trigger unexpected process or system termination. No authentication or network access is required—a malicious app running locally on the system can exploit this flaw. The patch is available in macOS Golden Gate 27, released September 14, 2026.
Affected products
- Apple macOS Golden Gate prior to 27
Timeline
- 2026-09-14: disclosed: CVE-2026-84558 disclosed; macOS Golden Gate 27 released with patch
- 2026-09-14: patched: Fixed in macOS Golden Gate 27