Junglewise Threat Intelligence

CVE-2026-84607: Apple kernel race condition in sandboxed apps

CVE-2026-84607 · Severity: high · CVSS 7.8 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS Golden Gate, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A race condition vulnerability in Apple's kernel allows a sandboxed application to execute arbitrary code with elevated kernel privileges. This bypasses Apple's sandbox security model, allowing malicious apps to gain unrestricted system access and potentially compromise user data, install persistent malware, or take complete control of the device. The vulnerability affects iPhone, iPad, Mac, Apple Watch, Apple TV, and Vision Pro devices.

Technical details

A race condition in kernel state management allows a sandboxed process to execute arbitrary code with kernel privileges. The vulnerability exists in multiple Apple operating systems and was fixed through improved state management logic. Attack requires a malicious app to be installed and executed on the device; no network access or user interaction beyond app installation is needed. A successful exploit grants kernel-level code execution, fully compromising the device's security boundaries. Patches are available in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.

Affected products

  • Apple iOS before 26.7 and 27
  • Apple iPadOS before 26.7 and 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-84607 disclosed; patches released
  • 2026-09-14: patched: Fixes released across all affected platforms

References

Related threats