• PATCH AVAILABLE

CVE-2026-84609: privilege escalation in Apple iOS and iPadOS

A malicious or vulnerable app can modify protected system files on affected Apple platforms, potentially allowing code or configuration tampering; this is tracked as CVE-2026-84609. The issue affects iOS and iPadOS before 27, macOS before 15.8 and 26.7 (and macOS branches listed before 27), tvOS, visionOS and watchOS before their 27 releases. An attacker needs to run or install an app on the device; the CVSS vector indicates no user interaction or prior privileges are required to trigger the flaw.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00665
CWE
CWE-120
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgently install the vendor updates: Apple published fixes in iOS/iPadOS 27 and macOS 15.8/26.7 and corresponding 27 releases—apply them to remove the ability for apps to modify protected files.

What is CVE-2026-84609?

A malicious or vulnerable app can modify protected system files on affected Apple platforms, potentially allowing code or configuration tampering; this is tracked as CVE-2026-84609. The issue affects iOS and iPadOS before 27, macOS before 15.8 and 26.7 (and macOS branches listed before 27), tvOS, visionOS and watchOS before their 27 releases. An attacker needs to run or install an app on the device; the CVSS vector indicates no user interaction or prior privileges are required to trigger the flaw.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 27.xbefore 2727
macOS 15.xbefore 15.815.8
macOS 26.xbefore 26.726.7
macOS 27.xbefore 2727
tvOS 27.xbefore 2727
visionOS 27.xbefore 2727
watchOS 27.xbefore 2727

Is CVE-2026-84609 being exploited?

There are no public reports of exploitation of CVE-2026-84609 as of 2026-09-29.

How to fix CVE-2026-84609

  1. Update iOS and iPadOS devices to version 27 or later.
  2. Update macOS devices to macOS 15.8, 26.7, or 27 as applicable; update tvOS, visionOS, and watchOS to 27 where available.
  3. Restrict installation of untrusted or unsigned apps and use mobile device management controls to limit app sources.
  4. Monitor endpoints for unexpected changes to system files and review app telemetry for suspicious activity.

Frequently asked questions

Is CVE-2026-84609 being actively exploited?

There are no public reports of exploitation of CVE-2026-84609 as of 2026-09-29.

Which iOS and iPadOS versions are affected by CVE-2026-84609?

iOS and iPadOS releases before 27 are affected; related Apple platforms listed include macOS releases before 15.8 and 26.7 and other OS branches prior to their 27 releases.

Is there a patch for CVE-2026-84609?

Yes. Apple released fixes in iOS and iPadOS 27 and in macOS 15.8, 26.7 and the various 27 branch releases; update devices to the stated fixed versions.

Does CVE-2026-84609 require authentication?

No. The vulnerability can be triggered without prior privileges or user interaction according to the reported vulnerability vector, meaning an app on the device can exploit it without additional authentication.

References