CVE-2026-84571Medium· 4.3▾ SunlitA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may lead to unexpected app termina…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
— → 4.3
none → medium
Last analysed / modified upstream
0.2% → 0.4%
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may lead to unexpected app termination.
ipados < 27.0iphone_os < 27.0macos < 27.0tvos < 27.0visionos < 27.0watchos < 27.0Upgrade past the affected range:
ipados 27.0iphone_os 27.0macos 27.0tvos 27.0visionos 27.0watchos 27.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84632High· 7.3The issue was addressed with improved memory handling
CVE-2026-84609Critical· 9.8A permissions issue was addressed with improved path validation
CVE-2026-84497High· 7.8A buffer overflow was addressed with improved size validation
CVE-2026-65398High· 7.8An out-of-bounds access issue was addressed with improved bounds checking
CVE-2026-84521Medium· 5.5A use after free issue was addressed with improved memory management
CVE-2026-65349Medium· 6.6An out-of-bounds read was addressed with improved input validation