Junglewise Threat Intelligence

CVE-2026-84565: Apple macOS out-of-bounds read in Accelerate Framework

CVE-2026-84565 · Severity: high · CVSS 7.1 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

The Accelerate Framework is a core macOS component used by applications to perform high-performance numerical computations and image processing. A vulnerability allows attackers to craft malicious disk images that, when processed, cause unexpected application termination, potentially disrupting user workflows or enabling denial of service attacks. No user interaction beyond processing a specially crafted file is required.

Technical details

An out-of-bounds read vulnerability exists in the Accelerate Framework's image processing functionality. The root cause is insufficient bounds checking when processing maliciously crafted disk images. The attack requires a local attacker to supply a malformed disk image file, which is then processed by a vulnerable application; no special privileges or network access are required. Successful exploitation causes unexpected process termination and denial of service. The vulnerability is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 via improved bounds checking.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7

References

Related threats