CVE-2026-84561
Apple · iOS, iPadOS, macOS, tvOS, visionOS, watchOS
A double free memory management vulnerability in multiple Apple operating systems allows an unauthenticated application to cause system termination or corrupt kernel memory.
Executive summary
A critical double free vulnerability affecting the Apple ecosystem allows unauthenticated attackers to trigger system crashes or corrupt sensitive kernel memory.
Vulnerability
This is a memory corruption flaw involving a double free issue within the kernel. The vulnerability can be triggered by an unauthenticated application, potentially leading to arbitrary code execution or system instability.
Business impact
The CVSS score of 9.8 reflects the high severity of this flaw, as it allows for total loss of system integrity and availability. Successful exploitation could result in full device compromise, theft of sensitive user data, or prolonged operational downtime across the enterprise fleet. Given that this affects the core kernel, the risk of lateral movement following a successful exploit is significant.
Remediation
Immediate Action: Update all affected Apple devices to the versions specified in the vendor security advisory (iOS/iPadOS 26.7 or 27, macOS 15.8/26.7 or 27, and respective versions for tvOS, visionOS, and watchOS).
Proactive Monitoring: Monitor device logs for recurrent system crashes or unexpected reboots that may indicate automated attempts to trigger the double free condition.
Compensating Controls: Implement mobile device management (MDM) policies to restrict the installation of unauthorized or unverified applications, reducing the attack surface for this exploit.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a severe risk to organizational security due to its potential for kernel-level exploitation. It is imperative that IT administrators prioritize the deployment of the identified patches across all managed Apple hardware immediately to prevent potential exploitation. Failure to update in a timely manner leaves enterprise endpoints exposed to complete system compromise.
More Apple CVEs all →
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.8 (3.1)
- Analyst report written