A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted volume may lead to unexpected system termination.

cve CVE-2026-84510 1 source, 1 claim · Watch

NVD writes:
A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted volume may lead to unexpected system termination. the claim

What it is to other things

affectsapple/ipados
NVD
affectsapple/iphone_os
NVD
affectsapple/macos
NVD
made_byapple
NVD

In words only, so not counted until a person confirms one:

affectsapple/ios_and_ipados
NVD says “Apple · iOS and iPadOS”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
NVD6.5
receipt
Source
NVD
Its words
6.5
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0896A319-539F-45D2-ACA1-7225AE5C06ED",
                "versionEndExcluding": "26.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "B331E4FC-727F-403B-8689-E647A51204FD",
                "versionEndExcluding": "26.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted volume may lead to unexpected system termination."
      }
    ],
    "id": "CVE-2026-84510",
    "lastModified": "2026-09-18T16:36:46.707",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-84510",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T14:47:38.596884Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:27.510",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149034"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149041"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-122"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDiOS and iPadOS
receipt
Source
NVD
Its words
iOS and iPadOS
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
2026-09-29 17:49 UTCiOS and iPadOS
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0896A319-539F-45D2-ACA1-7225AE5C06ED",
                "versionEndExcluding": "26.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "B331E4FC-727F-403B-8689-E647A51204FD",
                "versionEndExcluding": "26.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted volume may lead to unexpected system termination."
      }
    ],
    "id": "CVE-2026-84510",
    "lastModified": "2026-09-18T16:36:46.707",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-84510",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T14:47:38.596884Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:27.510",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149034"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149041"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-122"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0896A319-539F-45D2-ACA1-7225AE5C06ED",
                "versionEndExcluding": "26.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "B331E4FC-727F-403B-8689-E647A51204FD",
                "versionEndExcluding": "26.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted volume may lead to unexpected system termination."
      }
    ],
    "id": "CVE-2026-84510",
    "lastModified": "2026-09-18T16:36:46.707",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-84510",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T14:47:38.596884Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:27.510",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149034"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149041"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-122"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDApple
receipt
Source
NVD
Its words
Apple
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
2026-09-29 17:49 UTCApple
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0896A319-539F-45D2-ACA1-7225AE5C06ED",
                "versionEndExcluding": "26.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "B331E4FC-727F-403B-8689-E647A51204FD",
                "versionEndExcluding": "26.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted volume may lead to unexpected system termination."
      }
    ],
    "id": "CVE-2026-84510",
    "lastModified": "2026-09-18T16:36:46.707",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-84510",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T14:47:38.596884Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:27.510",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149034"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149041"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-122"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted volume may lead to unexpected system termination.
zetlyn/cve-nvd · 2026-09-14
cvss 6.5 product iOS and iPadOS status Analyzed vendor Apple source