Apple macOS Macintosh Operating System
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Apple macOS.
Recent Apple macOS Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 149035 | macOS Golden Gate 27 - Apple Security Content | September 14, 2026 |
| 149042 | macOS Tahoe 26.7 - Apple Security Content | September 14, 2026 |
| 149043 | macOS Sequoia 15.8 - Apple Security Content | September 14, 2026 |
| 148281 | macOS Tahoe 26.6.2 - Apple Security Content | August 17, 2026 |
| 148171 | macOS Sequoia 15.7.9 - Apple Security Content | August 6, 2026 |
| 148170 | macOS Tahoe 26.6.1 - Apple Security Content | August 6, 2026 |
| 148172 | macOS Sonoma 14.8.9 - Apple Security Content | August 6, 2026 |
| 128072 | macOS Sonoma 14.8.8 - Apple Security Content | July 27, 2026 |
| 128071 | macOS Sequoia 15.7.8 - Apple Security Content | July 27, 2026 |
| 128067 | macOS Tahoe 26.6 - Apple Security Content | July 27, 2026 |
Known Exploited Apple macOS Vulnerabilities
The following Apple macOS vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Apple macOS Improper Authentication Vulnerability |
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. CVE-2026-65400 |
August 18, 2026 |
| Apple macOS Use-After-Free Vulnerability |
Apple macOS contains a use-after-free vulnerability that could allow for privilege escalation. CVE-2019-8526 Exploit Probability: 0.7% |
April 17, 2023 |
| Apple macOS Out-of-Bounds Write Vulnerability |
macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges. CVE-2022-22675 Exploit Probability: 12.5% |
April 4, 2022 |
| Apple macOS Out-of-Bounds Read Vulnerability |
macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory. CVE-2022-22674 Exploit Probability: 1.1% |
April 4, 2022 |
| Apple macOS Input Validation Error |
A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited. CVE-2021-30713 Exploit Probability: 7.0% |
November 3, 2021 |
| Apple macOS Policy Subsystem Gatekeeper Bypass |
A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited. CVE-2021-30657 Exploit Probability: 68.5% |
November 3, 2021 |
The vulnerability CVE-2021-30657: Apple macOS Policy Subsystem Gatekeeper Bypass is in the top 1% of the currently known exploitable vulnerabilities. The vulnerability CVE-2022-22675: Apple macOS Out-of-Bounds Write Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.
Apple macOS EOL Dates
Ensure that you are using a supported version of Apple macOS. Here are some end of life, and end of support dates for Apple macOS.
| Release | EOL Date | Status |
|---|---|---|
| 26 | - |
Active
|
| 15 | - |
Active
|
| 14 | - |
Active
|
| 13 | September 15, 2025 |
EOL
Apple macOS 13 became EOL in 2025. |
| 12 | September 16, 2024 |
EOL
Apple macOS 12 became EOL in 2024. |
| 11 | February 2, 2026 |
EOL
Apple macOS 11 became EOL in 2026. |
| 10.15 | February 2, 2026 |
EOL
Apple macOS 10.15 became EOL in 2026. |
| 10.14 | October 25, 2021 |
EOL
Apple macOS 10.14 became EOL in 2021. |
| 10.13 | December 1, 2020 |
EOL
Apple macOS 10.13 became EOL in 2020. |
| 10.12 | October 1, 2019 |
EOL
Apple macOS 10.12 became EOL in 2019. |
| 10.11 | December 1, 2018 |
EOL
Apple macOS 10.11 became EOL in 2018. |
| 10.9 | December 1, 2016 |
EOL
Apple macOS 10.9 became EOL in 2016. |
| 10.8 | August 13, 2015 |
EOL
Apple macOS 10.8 became EOL in 2015. |
| 10.7 | October 4, 2012 |
EOL
Apple macOS 10.7 became EOL in 2012. |
| 10.6 | July 25, 2011 |
EOL
Apple macOS 10.6 became EOL in 2011. |
| 10.5 | August 13, 2009 |
EOL
Apple macOS 10.5 became EOL in 2009. |
| 10.4 | November 14, 2007 |
EOL
Apple macOS 10.4 became EOL in 2007. |
| 10.3 | April 15, 2005 |
EOL
Apple macOS 10.3 became EOL in 2005. |
| 10.2 | October 3, 2003 |
EOL
Apple macOS 10.2 became EOL in 2003. |
| 10.1 | June 6, 2002 |
EOL
Apple macOS 10.1 became EOL in 2002. |
By the Year
In 2026 there have been 732 vulnerabilities in Apple macOS with an average score of 6.8 out of ten. Last year, in 2025 macOS had 679 security vulnerabilities published. That is, 53 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.15.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 732 | 6.77 |
| 2025 | 679 | 6.62 |
| 2024 | 543 | 6.42 |
| 2023 | 427 | 6.73 |
| 2022 | 381 | 7.10 |
| 2021 | 500 | 7.01 |
| 2020 | 342 | 7.24 |
| 2019 | 305 | 7.62 |
| 2018 | 89 | 7.25 |
It may take a day or so for new macOS vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Apple macOS Security Vulnerabilities
Apple OSes Type Confusion DFS before 27 via memory handling
CVE-2026-65409
5.5 - Medium
- September 14, 2026
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause a denial of service.
Object Type Confusion
macOS file permissions issue allows privileged access before 27/15.8
CVE-2026-84559
- September 14, 2026
A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious application may be able to access restricted files.
macOS 27/15.8/26.7: State Management Logic Issue Allows Protected Data Access
CVE-2026-43741
5.5 - Medium
- September 14, 2026
A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access protected user data.
Authorization
macOS Golden Gate State MGmt Flaw: App Access Sensitive Data
CVE-2026-28937
5.5 - Medium
- September 14, 2026
This issue was addressed through improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.
Authorization
Apple OS OOB Write (fixed in iOS 26.7/27)
CVE-2026-86876
5.2 - Medium
- September 14, 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. A sandboxed process may be able to circumvent sandbox restrictions.
Memory Corruption
Apple Safari 27: Exfiltration of installed apps via state management
CVE-2026-84518
4.3 - Medium
- September 14, 2026
This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious website may be able to determine what apps a user has installed.
External Control of Critical State Data
Privilege Escalation via Entitlement Check Bypass in macOS Golden Gate
CVE-2026-84631
7.8 - High
- September 14, 2026
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to gain root privileges.
Improper Handling of Insufficient Permissions or Privileges
Apple macOS Logic Flaw Unexpected Termination (GG 27, Sequoia 15.8, Tahoe 26.7)
CVE-2026-84563
7.5 - High
- September 14, 2026
A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.
Object Type Confusion
File Write via Malicious Archive in iOS/iPadOS 26.7+, macOS 27+, visionOS 27
CVE-2026-84534
5.5 - Medium
- September 14, 2026
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. Extracting a maliciously crafted archive may allow an attacker to write arbitrary files.
Directory traversal
macOS Kernel Memory Read via Race Condition (Fixed in 27, 15.8, 26.7)
CVE-2026-43690
- September 14, 2026
A race condition was addressed with improved locking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A local user may be able to read kernel memory.
Race Condition in macOS State Management Enables Sensitive Data Access
CVE-2026-84522
- September 14, 2026
A race condition was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.
macOS Gatekeeper Bypass via Logic Issue in State Management
CVE-2026-86909
- September 14, 2026
A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass Gatekeeper checks.
Apple OS kernel use-after-free via NFS (fixed in 26.7/27)
CVE-2026-43686
8.8 - High
- September 14, 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may lead to kernel memory corruption.
Dangling pointer
Apple OS OOB Write in File Processing (Fixed in iOS 27, macOS 15.8)
CVE-2026-84575
7.8 - High
- September 14, 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted file may lead to unexpected app termination.
Memory Corruption
Path Handling Vulnerability in Apple OS (iOS/iPadOS <27, macOS <27)
CVE-2026-64756
5.5 - Medium
- September 14, 2026
A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.
Directory traversal
Apple Xcode/macOS Golden Gate Permission Validation Flaw
CVE-2026-65393
5.5 - Medium
- September 14, 2026
A permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An app may be able to access user-sensitive data.
AuthZ
Memory init flaw in Apple OS (fixed in iOS 26.7, iPadOS 26.7, macOS 27)
CVE-2026-65405
5.5 - Medium
- September 14, 2026
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to determine kernel memory layout.
Use of Uninitialized Variable
macOS root privilege escalation via permissions flaw fixed in 15.7.8/26.6
CVE-2026-64701
7.8 - High
- September 14, 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
Improper Handling of Insufficient Permissions or Privileges
macOS Authorization Flaw allows data access prior to 27/15.8
CVE-2026-84555
5.5 - Medium
- September 14, 2026
An authorization issue was addressed with improved access control. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8. An app may be able to access sensitive user data.
Authorization
macOS Integer Overflow in Input Validation Causing DoS (Fixed 27, 15.8, 26.7)
CVE-2026-65413
5.5 - Medium
- September 14, 2026
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause a denial of service.
Integer Overflow or Wraparound
Apple OS Kernel Race Condition Leading to Termination (fixed iOS 18.7.10)
CVE-2026-64717
6.3 - Medium
- September 14, 2026
A race condition was addressed with improved state handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
Race Condition
Out-of-bounds SMB access in macOS Kernel pre-Sequoia 15.8
CVE-2026-84543
7.5 - High
- September 14, 2026
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory.
Out-of-bounds Read
macOS FS Mod via Entitlement Bypass (pre-27)
CVE-2026-84514
- September 14, 2026
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to modify protected parts of the file system.
macOS OOB Write in Disk Image Mounting (fixed in 15.7.8/14.8.8/26.6)
CVE-2026-43761
6.5 - Medium
- September 14, 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Mounting a malicious disk image may cause unexpected system termination.
Memory Corruption
macOS Sandbox Breakout (Pre-27 Golden Gate, Pre-15.8 Sequoia, Pre-26.7 Tahoe)
CVE-2026-84580
- September 14, 2026
The issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.
Apple OS OOB Write via Malicious 3D Model (Fixed in 26.7/27)
CVE-2026-84611
7.3 - High
- September 14, 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption.
Memory Corruption
Apple OSs: Race Condition Causing Unexpected Termination (CVE202684492)
CVE-2026-84492
4.7 - Medium
- September 14, 2026
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.
Race Condition
macOS DoS via bad input validation (fixed in 27, 15.8, 26.7)
CVE-2026-84538
6.5 - Medium
- September 14, 2026
A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause a denial-of-service.
Improper Input Validation
Race condition in Apple iOS 26.7 allows kernel-priv exec via sandboxed app
CVE-2026-84607
7.8 - High
- September 14, 2026
A race condition was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A sandboxed app may be able to execute arbitrary code with kernel privileges.
Race Condition
Apple Keychain Credential Deletion Vulnerability in iOS/macOS/visionOS 27
CVE-2026-86905
5.5 - Medium
- September 14, 2026
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to delete credentials stored in Keychain.
Authorization
Apple OS Font Engine OOB Read Exposes Process Memory
CVE-2026-84596
6.5 - Medium
- September 14, 2026
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted font may result in the disclosure of process memory.
Out-of-bounds Read
macOS Sandbox Breakout Logic Issue Fixed in 27, 15.8, 26.7
CVE-2026-84578
- September 14, 2026
A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.
Out-of-Bounds Read in Apple OS Font Parsing (CVE-2026-84597)
CVE-2026-84597
6.5 - Medium
- September 14, 2026
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted font may result in the disclosure of process memory.
Out-of-bounds Read
Apple iOS 26.7/iPadOS 26.7 App Data Leakage Vulnerability
CVE-2026-43664
5.5 - Medium
- September 14, 2026
This issue was addressed with improved data protection. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access sensitive user data.
Information Disclosure
Apple iOS Identifier Privacy Leak Across Reinstalls
CVE-2026-84606
7.5 - High
- September 14, 2026
A privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to identify a user across reinstalls.
Use of Insufficiently Random Values
Use-After-Free in Apple OS 26.6 (iOS, macOS, tvOS, watchOS, iPadOS)
CVE-2026-43808
5.5 - Medium
- September 14, 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
Dangling pointer
Auth Issue: Motion Data from Headphones Access without Consent (iOS 26.7+)
CVE-2026-43737
5.5 - Medium
- September 14, 2026
An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access motion data from headphones without user consent.
AuthZ
macOS Disk Image Buffer Overflow (fixed v27/15.8/26.7)
CVE-2026-84581
8.4 - High
- September 14, 2026
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory.
Classic Buffer Overflow
Apple macOS Golden Gate Sandbox Escape (CVE-2026-86894)
CVE-2026-86894
7.5 - High
- September 14, 2026
A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out of its sandbox.
Protection Mechanism Failure
macOS OOB Write via SMB, fixed in 27, Sequoia 15.8, Tahoe 26.7
CVE-2026-84515
7.8 - High
- September 14, 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to kernel memory corruption.
Memory Corruption
Apple WebKit Null Pointer Deref in Web Content (iOS 26.7+, macOS 15.8+)
CVE-2026-65412
6.5 - Medium
- September 14, 2026
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. Processing web content may lead to a denial-of-service.
NULL Pointer Dereference
Apple iOS/iPadOS Auth Bypass via State Management (18.7.10)
CVE-2026-65404
5.5 - Medium
- September 14, 2026
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A malicious application may be able to bypass Privacy preferences.
AuthZ
macOS Integer Overflow DoS Fixed in GA 27/Sequoia 15.8/Tahoe 26.7
CVE-2026-84554
5.9 - Medium
- September 14, 2026
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to cause a denial-of-service.
Integer Overflow or Wraparound
Apple OS ImageIO OOB Write pre 26.7
CVE-2026-86882
6.5 - Medium
- September 14, 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may lead to unexpected process termination.
Memory Corruption
macOS State Mgmt Overrides Privacy Bypass pre27/15.8/26.7
CVE-2026-84574
- September 14, 2026
A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to bypass Privacy preferences.
Apple OS Kernel Memory Disclosure via NFS Client (CVE-2026-43687)
CVE-2026-43687
6.5 - Medium
- September 14, 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may disclose kernel memory.
Information Disclosure
Apple iOS/iPadOS/macOS Buffer Overflow before 18.7.10/27/15.7.8/14.8.8
CVE-2026-84489
5.5 - Medium
- September 14, 2026
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to cause a denial of service.
Classic Buffer Overflow
Kernel Memory OOB Write in Apple OS (iOS <26.7, macOS <15.8)
CVE-2026-84523
5.5 - Medium
- September 14, 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or write kernel memory.
Memory Corruption
macOS Root Priv Escal Path Handling in 27/15.8/26.7
CVE-2026-43691
7.8 - High
- September 14, 2026
A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
Directory traversal
macOS Sandbox Breakout Authz Issue Fixed in Golden Gate 27
CVE-2026-84535
8.2 - High
- September 14, 2026
An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.
Authorization
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Apple macOS or by Apple? Click the Watch button to subscribe.