Junglewise Threat Intelligence

CVE-2026-86882: Apple Accelerate Framework out-of-bounds write in image processing

CVE-2026-86882 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

Apple's Accelerate Framework processes images for iOS, iPadOS, macOS, and related platforms. A maliciously crafted image can cause unexpected app termination due to an out-of-bounds write vulnerability. While the impact is limited to denial of service, this could disrupt user operations if exploited.

Technical details

An out-of-bounds write vulnerability exists in Apple's Accelerate Framework image processing component. The vulnerability occurs when processing maliciously crafted image files, allowing memory to be written outside valid bounds due to insufficient bounds checking. The attack vector requires user interaction (processing a crafted image), and no authentication is required. An attacker can trigger unexpected process termination and potentially cause denial of service. The vulnerability has been patched in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: patched: iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 released

References

Related threats