Junglewise Threat Intelligence

CVE-2026-84596: Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS out-of-bounds read in font processing

CVE-2026-84596 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS, Apple macOS Golden Gate, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A font parsing vulnerability in Apple's operating systems allows attackers to craft malicious font files that trigger an out-of-bounds memory read. When a user opens an affected app or visits a website that loads the malicious font, sensitive information from the device's memory could be disclosed, potentially exposing passwords, authentication tokens, or other confidential data.

Technical details

This is an out-of-bounds read vulnerability in font processing code across Apple's operating system family. The root cause is insufficient bounds checking when parsing maliciously crafted font files. An attacker can craft a font file with invalid structural data that causes the font parser to read memory beyond allocated buffer boundaries. The attack is triggered passively when an application or web page attempts to render the malicious font; no special privileges or authentication are required. The vulnerability allows disclosure of arbitrary process memory, which may contain sensitive secrets. The issue is fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27 released September 14, 2026.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: patched: Fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27
  • 2026-09-14: disclosed: CVE-2026-84596 published

References

Related threats