Junglewise Threat Intelligence

CVE-2026-84620: Apple iOS and macOS integer overflow in 3D model processing

CVE-2026-84620 · Severity: high · CVSS 7.3 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS Golden Gate, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A vulnerability in how Apple's operating systems process 3D models can cause memory corruption when users open maliciously crafted 3D files. An attacker can crash the application, disrupt service, or potentially execute code without any user action beyond opening a file. This affects millions of iPhones, iPads, and Macs, and Apple has released patches across all affected platforms.

Technical details

An integer overflow vulnerability exists in the 3D model processing component of Apple's operating systems, allowing attackers to bypass bounds checking and cause memory corruption. The vulnerability is triggered when processing maliciously crafted 3D model files; no authentication or user interaction beyond opening the file is required. An attacker can exploit this to cause unexpected process termination (denial of service) or potentially achieve memory corruption leading to arbitrary code execution. Apple addressed this with improved input validation and bounds checking, with patches released on September 14, 2026 across iOS 26.7+, iPadOS 26.7+, macOS Golden Gate 27, macOS Sequoia 15.8, and other supported OS versions.

Affected products

  • Apple iOS before 26.7, before 27
  • Apple iPadOS before 26.7, before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-84620 published; patches released
  • 2026-09-14: patched: iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27

References

Related threats