DIRAS TAKE
Urgent: install the macOS Golden Gate 27 update because the flaw permits local corruption of kernel memory, which can result in system crashes or privilege escalation. If you cannot patch immediately, restrict who can run code locally and increase endpoint monitoring for crashes and suspicious kernel activity.
What is CVE-2026-84520?
A local attacker can trigger a buffer overflow in macOS that may crash the system or corrupt kernel memory, potentially leading to privilege escalation or denial of service. This is CVE-2026-84520. Apple fixed the flaw in macOS Golden Gate 27; releases prior to 27 on the 27.x branch are affected. An attacker must have local access to the machine to exploit the issue; there are no facts here indicating remote network exploitation is possible without local code execution or user interaction.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple macOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 27.x | before 27 | 27 |
Is CVE-2026-84520 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-84520
- Install macOS Golden Gate 27 on affected systems (fixed in 27).
- Restrict local access and limit ability to run untrusted binaries on macOS hosts.
- Monitor endpoints for unexpected system terminations and kernel-related error logs.
- Follow Apple’s security guidance and apply updates from the vendor promptly.
Frequently asked questions
Is CVE-2026-84520 being actively exploited?
There are no public reports of exploitation as of 2026-09-29.
Which macOS versions are affected by CVE-2026-84520?
macOS releases before Golden Gate 27 on the 27.x branch are affected; the issue is fixed in version 27.
Is there a patch for CVE-2026-84520?
Yes. Apple fixed the vulnerability in macOS Golden Gate 27; apply that update to remediate the issue.
Does CVE-2026-84520 require authentication?
Exploitation requires local access to the macOS system; there is no indication that remote unauthenticated network access is sufficient.
References
- nvd.nist.gov/vuln/detail/CVE-2026-84520
- cve.org/CVERecord?id=CVE-2026-84520
- support.apple.com/en-us/149035
- All Apple CVEs on CVE Radar
- CVEs published in September 2026