Junglewise Threat Intelligence

CVE-2026-86876: Apple Accelerate Framework out-of-bounds write in image processing

CVE-2026-86876 · Severity: medium · CVSS 5.2 · Published 2026-09-14

Technologies: Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

The Accelerate Framework is a core Apple library used for image and signal processing across iOS, iPadOS, and macOS. A crafted image can cause a memory safety error that terminates the affected process unexpectedly, disrupting user experience and potentially providing a foothold for further exploitation.

Technical details

This is an out-of-bounds write vulnerability in the Accelerate Framework's image processing code. The root cause is insufficient bounds checking when processing maliciously crafted image data. The attack vector is local and does not require authentication; a user simply needs to view or process a malicious image file. An attacker can achieve denial of service via process termination, and potentially escalate privileges or achieve code execution depending on how the framework is used in privileged contexts. Apple patched this in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 with improved bounds checking.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats