Executive brief
Apple iOS, iPadOS, and macOS contain an uninitialized memory vulnerability in image processing that could expose sensitive data from the device's memory when a user opens a maliciously crafted image. An attacker could capture confidential information such as passwords, encryption keys, or personal data that was previously stored in memory. This vulnerability affects millions of users across iPhones, iPads, and Mac computers.
Technical details
The vulnerability is an uninitialized memory issue in Apple's image processing code where the application fails to properly initialize memory buffers before use. When processing a crafted malicious image, uninitialized memory containing previous process data may be read and disclosed to an attacker. The attack vector is network/local (via opening an image file or receiving it through messaging/web), requires user interaction to open the malicious image, and does not require authentication or system privileges. The impact is information disclosure of process memory; an attacker cannot achieve code execution but can extract sensitive data that was previously in memory. Patches are available in iOS 26.7+, iPadOS 26.7+, iOS 27+, iPadOS 27+, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.
Affected products
- Apple iOS before 26.7 and before 27
- Apple iPadOS before 26.7 and before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
- Apple macOS Golden Gate before 27
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed: CVE-2026-84564 published and patches released
- 2026-09-14: patched: iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27 released