Junglewise Threat Intelligence

CVE-2026-84572: Apple macOS out-of-bounds read in kernel memory

CVE-2026-84572 · Severity: high · CVSS 7.1 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

macOS is the operating system that runs Apple's Mac computers and handles core system functions including memory management and application isolation. An out-of-bounds read vulnerability allows a malicious app to read sensitive kernel memory or cause the system to crash unexpectedly, potentially exposing confidential data or disrupting normal operations.

Technical details

This is an out-of-bounds read vulnerability in macOS kernel memory handling, addressed through improved bounds checking. The vulnerability allows a local application to read kernel memory that should be inaccessible, potentially disclosing sensitive system data. Attack vector is local (requires app execution on the affected system). An attacker can trigger unexpected system termination or exfiltrate kernel memory contents. The issue is patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed: CVE-2026-84572 disclosed; patches released in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7

References

Related threats