Executive brief
Apple operating systems contain a type confusion vulnerability in core system libraries that can cause unexpected app crashes or system termination. An attacker can trigger this issue by crafting a malicious app, resulting in denial of service to affected devices and potential disruption of user workflows.
Technical details
A type confusion vulnerability exists in Apple's core system libraries that allows improper type handling during object processing. The vulnerability is triggered when an app processes specially crafted data, leading to unexpected type interpretation and subsequent system termination. The attack requires local code execution (app installation) with no user interaction needed beyond normal app usage. An attacker can cause denial of service through unexpected process termination. The vulnerability is addressed through improved type checking in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.
Affected products
- Apple iOS before 27; before 26.7 for iOS 26
- Apple iPadOS before 27; before 26.7 for iPadOS 26
- Apple macOS Golden Gate before 27; Sequoia before 15.8; Tahoe before 26.7
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed: CVE-2026-84602 disclosed; patches released for iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27