Junglewise Threat Intelligence

CVE-2026-84567: macOS memory handling denial of service

CVE-2026-84567 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

An app running on macOS can trigger unexpected system termination due to improper memory handling. This denial-of-service vulnerability can crash a Mac system, disrupting user work and operations. While the vulnerability requires local app execution, it poses a risk when users run untrusted applications or if a legitimate app is compromised.

Technical details

CVE-2026-84567 is a memory handling vulnerability in macOS that allows a local application to cause unexpected system termination. The root cause involves improper memory management in a core OS component, addressed through improved memory handling routines. An attacker would need to execute a malicious app locally on the target system to trigger the vulnerability—network remote exploitation is not possible. The issue results in denial of service via system crash. Apple patched this in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 released on September 14, 2026.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed: CVE-2026-84567 disclosed; patches released for macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7
  • 2026-09-14: patched: Fix available in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7

References

Related threats