DIRAS TAKE
Treat this as urgent: the flaw is exploitable over the network without authentication or user interaction (CVSS AV:N/PR:N/UI:N), and vendor patches are already available.
What is CVE-2026-84561?
An unauthenticated network attacker can exploit CVE-2026-84561 to trigger a double free in Apple operating systems that may lead to unexpected system termination, kernel memory corruption, or remote code execution. CVE-2026-84561 affects iOS and iPadOS before 26.7 (26.x) and before 27 (27.x); related fixes are available for macOS, tvOS, visionOS, and watchOS as listed below. The vulnerability requires no privileges and no user interaction but is reachable over a network.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple iOS and iPadOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 26.x | before 26.7 | 26.7 |
| iOS and iPadOS 27.x | before 27 | 27 |
| macOS 15.x | before 15.8 | 15.8 |
| macOS 26.x | before 26.7 | 26.7 |
| macOS 27.x | before 27 | 27 |
| tvOS 27.x | before 27 | 27 |
| visionOS 27.x | before 27 | 27 |
| watchOS 27.x | before 27 | 27 |
Is CVE-2026-84561 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-84561
- Apply the vendor updates: iOS/iPadOS 26.7 or 27, macOS 15.8, macOS 26.7, macOS 27, tvOS 27, visionOS 27, watchOS 27.
- If you cannot patch immediately, restrict network exposure of affected devices and services to trusted networks only.
- Monitor system and kernel logs for crashes or anomalous behavior and investigate unexpected reboots or memory corruption.
- Follow Apple's security guidance and deploy updates in your mobile device management or patching workflow promptly.
Frequently asked questions
Is CVE-2026-84561 being actively exploited?
There are no public reports of exploitation of CVE-2026-84561 as of 2026-09-29.
Which iOS and iPadOS versions are affected by CVE-2026-84561?
iOS and iPadOS releases before 26.7 (26.x) and before 27 (27.x) are affected; update to 26.7 or 27 to remediate.
Is there a patch for CVE-2026-84561?
Yes. Apple released fixes in iOS and iPadOS 26.7 and 27, and corresponding updates for macOS 15.8, macOS 26.7, macOS 27, tvOS 27, visionOS 27, and watchOS 27.
Does CVE-2026-84561 require authentication?
No. The vulnerability does not require authentication or user interaction and is reachable over a network.
References
- nvd.nist.gov/vuln/detail/CVE-2026-84561
- cve.org/CVERecord?id=CVE-2026-84561
- support.apple.com/en-us/149034
- support.apple.com/en-us/149035
- support.apple.com/en-us/149036
- support.apple.com/en-us/149037
- support.apple.com/en-us/149038
- support.apple.com/en-us/149041
- support.apple.com/en-us/149042
- support.apple.com/en-us/149043
- All Apple CVEs on CVE Radar
- CVEs published in September 2026