CVE-2026-84505

7.8

Apple · macOS

A local out-of-bounds write vulnerability in macOS allows a malicious application to gain root privileges through insufficient bounds checking.

Executive summary

A high-severity out-of-bounds write vulnerability in Apple macOS enables local attackers to escalate privileges to root, posing a significant risk to system integrity.

Vulnerability

This vulnerability is an out-of-bounds write flaw caused by insufficient memory bounds checking. A locally authenticated user, typically running a malicious application, can exploit this to achieve arbitrary code execution with root privileges.

Business impact

The ability for a standard application to escalate to root privileges represents a total compromise of the affected system. An attacker with root access can bypass all security controls, exfiltrate sensitive data, install persistent backdoors, or disable security software. With a CVSS score of 7.8, this flaw is considered high-risk due to the potential for complete system takeover by local actors.

Remediation

Immediate Action: Update all affected macOS installations to the patched versions: macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27.

Proactive Monitoring: Monitor system logs for unexpected privilege escalation events or suspicious execution patterns by non-privileged applications.

Compensating Controls: Implement strict application sandboxing and restrict the ability of unauthorized users to install or execute untrusted third-party software on endpoints.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a clear path to full system compromise for local attackers. IT and security teams should prioritize the deployment of the identified macOS updates across all managed devices to neutralize the risk of unauthorized privilege escalation. Failure to patch may allow attackers to bypass standard OS security boundaries.

More Apple CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources