---
id: CVE-2026-84489
title: A buffer overflow was addressed with improved bounds checking
summary: >-
  A buffer overflow was addressed with improved bounds checking. This issue is
  fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden
  Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to
  cause a de…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-120
vendor: apple
product: ipados
affected:
  - ipados < 18.7.10
  - iphone_os < 18.7.10
  - 'macos >= 14.0, < 14.8.8'
  - 'macos >= 15.0, < 15.7.8'
patched:
  - ipados 18.7.10
  - iphone_os 18.7.10
  - macos 15.7.8
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T01:08:31.997'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84489'
references:
  - url: 'https://support.apple.com/en-us/128071'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/128072'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/148287'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/149034'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/149035'
    label: product-security@apple.com
tags:
  - nvd
  - cve.org
epss: 0.0017
epssPercentile: 0.06722
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T15:25:38.994715Z'
ingestedAt: '2026-09-14T21:15:17.482Z'
---

## Overview

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to cause a denial of service.

## Affected

- `ipados < 18.7.10`
- `iphone_os < 18.7.10`
- `macos >= 14.0, < 14.8.8`
- `macos >= 15.0, < 15.7.8`

## Remediation

Upgrade past the affected range:

- `ipados 18.7.10`
- `iphone_os 18.7.10`
- `macos 15.7.8`
