• PATCH AVAILABLE

CVE-2026-84561: pre-auth double free in Apple iOS and iPadOS

An unauthenticated network attacker can exploit CVE-2026-84561 to trigger a double free in Apple operating systems that may lead to unexpected system termination, kernel memory corruption, or remote code execution. CVE-2026-84561 affects iOS and iPadOS before 26.7 (26.x) and before 27 (27.x); related fixes are available for macOS, tvOS, visionOS, and watchOS as listed below. The vulnerability requires no privileges and no user interaction but is reachable over a network.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.0068
CWE
CWE-415
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as urgent: the flaw is exploitable over the network without authentication or user interaction (CVSS AV:N/PR:N/UI:N), and vendor patches are already available.

What is CVE-2026-84561?

An unauthenticated network attacker can exploit CVE-2026-84561 to trigger a double free in Apple operating systems that may lead to unexpected system termination, kernel memory corruption, or remote code execution. CVE-2026-84561 affects iOS and iPadOS before 26.7 (26.x) and before 27 (27.x); related fixes are available for macOS, tvOS, visionOS, and watchOS as listed below. The vulnerability requires no privileges and no user interaction but is reachable over a network.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 26.xbefore 26.726.7
iOS and iPadOS 27.xbefore 2727
macOS 15.xbefore 15.815.8
macOS 26.xbefore 26.726.7
macOS 27.xbefore 2727
tvOS 27.xbefore 2727
visionOS 27.xbefore 2727
watchOS 27.xbefore 2727

Is CVE-2026-84561 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-84561

  1. Apply the vendor updates: iOS/iPadOS 26.7 or 27, macOS 15.8, macOS 26.7, macOS 27, tvOS 27, visionOS 27, watchOS 27.
  2. If you cannot patch immediately, restrict network exposure of affected devices and services to trusted networks only.
  3. Monitor system and kernel logs for crashes or anomalous behavior and investigate unexpected reboots or memory corruption.
  4. Follow Apple's security guidance and deploy updates in your mobile device management or patching workflow promptly.

Frequently asked questions

Is CVE-2026-84561 being actively exploited?

There are no public reports of exploitation of CVE-2026-84561 as of 2026-09-29.

Which iOS and iPadOS versions are affected by CVE-2026-84561?

iOS and iPadOS releases before 26.7 (26.x) and before 27 (27.x) are affected; update to 26.7 or 27 to remediate.

Is there a patch for CVE-2026-84561?

Yes. Apple released fixes in iOS and iPadOS 26.7 and 27, and corresponding updates for macOS 15.8, macOS 26.7, macOS 27, tvOS 27, visionOS 27, and watchOS 27.

Does CVE-2026-84561 require authentication?

No. The vulnerability does not require authentication or user interaction and is reachable over a network.

References