Junglewise Threat Intelligence

CVE-2026-84575: Apple iOS, iPadOS, and macOS out-of-bounds write in Accelerate Framework

CVE-2026-84575 · Severity: high · CVSS 7.8 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS Golden Gate, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Apple's Accelerate Framework, a core component used for image and audio processing across iOS, iPadOS, and macOS devices, contains an out-of-bounds write vulnerability. An attacker can trigger this flaw by supplying a maliciously crafted image file, causing the application processing it to crash unexpectedly. While the immediate impact is service disruption, out-of-bounds writes can potentially be exploited for more severe outcomes depending on memory layout and attacker sophistication.

Technical details

CVE-2026-84575 is an out-of-bounds write vulnerability in Apple's Accelerate Framework that arises from insufficient bounds checking during image processing. The vulnerability is triggered when a maliciously crafted image file is processed, leading to a write operation beyond allocated buffer boundaries. Attack vector is local and requires user interaction (opening/processing a crafted image); no network access or privileged authentication is necessary. The immediate impact is unexpected application termination (denial of service); however, out-of-bounds writes can theoretically enable code execution depending on memory conditions. The flaw has been patched in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27, all released on September 14, 2026.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-84575 disclosed as part of iOS 27, iPadOS 27, and macOS security updates
  • 2026-09-14: patched: Patched in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27

References

Related threats