---
id: CVE-2026-84531
title: An out-of-bounds write issue was addressed with improved bounds checking
summary: >-
  An out-of-bounds write issue was addressed with improved bounds checking. This
  issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. Processing
  maliciously crafted NTLM input may lead to unexpected app termination.
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-787
vendor: apple
product: ipados
affected:
  - ipados < 27.0
  - iphone_os < 27.0
  - macos < 27.0
patched:
  - ipados 27.0
  - iphone_os 27.0
  - macos 27.0
published: '2026-09-14'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T17:22:07.960'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84531'
references:
  - url: 'https://support.apple.com/en-us/149034'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/149035'
    label: product-security@apple.com
tags:
  - nvd
  - cve.org
epss: 0.00149
epssPercentile: 0.03432
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T15:36:19.426466Z'
ingestedAt: '2026-09-14T21:15:17.528Z'
---

## Overview

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. Processing maliciously crafted NTLM input may lead to unexpected app termination.

## Affected

- `ipados < 27.0`
- `iphone_os < 27.0`
- `macos < 27.0`

## Remediation

Upgrade past the affected range:

- `ipados 27.0`
- `iphone_os 27.0`
- `macos 27.0`
