Junglewise Threat Intelligence

CVE-2026-84632: Apple iOS and macOS 3D model memory corruption

CVE-2026-84632 · Severity: high · CVSS 7.3 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS Golden Gate, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Apple's iOS, iPadOS, and macOS operating systems contain a memory corruption vulnerability triggered when processing maliciously crafted 3D models. An attacker could exploit this by distributing a specially crafted 3D file that crashes applications or potentially executes arbitrary code when opened. Apple has patched this issue across all affected platforms.

Technical details

This vulnerability is a memory corruption issue in the 3D model processing subsystem across Apple platforms. The root cause appears to be improper memory handling when parsing maliciously crafted 3D model files. The attack requires user interaction—a user must open or process a specially crafted 3D model file—making the attack vector local rather than network-based. Successful exploitation can lead to denial of service (application crash) or potentially memory corruption enabling code execution. The issue has been resolved through improved memory handling in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.

Affected products

  • Apple iOS before 26.7 and before 27
  • Apple iPadOS before 26.7 and before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-84632 disclosed; patches released for iOS 27, iPadOS 27, macOS Golden Gate 27, and other platforms
  • 2026-09-14: patched: Fixed in iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27

References

Related threats