Junglewise Threat Intelligence

CVE-2026-84566: Apple iOS and macOS kernel memory corruption

CVE-2026-84566 · Severity: high · CVSS 7.8 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Apple iOS, iPadOS, and macOS contain a memory handling vulnerability in kernel-level components that could allow a local attacker to cause unexpected system crashes or corrupt kernel memory. An exploit would require local access to a device and could result in system instability, denial of service, or potential privilege escalation.

Technical details

The vulnerability is an out-of-bounds write issue in kernel memory handling within APFS (Apple File System) and related components. The attack vector is local; a malicious application can trigger the out-of-bounds write by processing specially crafted input or mounting disk images with malicious files. An attacker with local code execution capabilities can cause unexpected system termination or corrupt kernel memory, potentially leading to privilege escalation or denial of service. The issue was addressed through improved bounds checking in memory operations. Patches are available in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple iOS before 26.7, before 27
  • Apple iPadOS before 26.7, before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed

References

Related threats