Apple Fixes APFS, Kernel, and PPP Issues I Reported - CVE-2026-84523
In security updates released on September 14, 2026, Apple credited me for security issues I had previously reported affecting APFS, the Kernel, and ppp. The APFS vulnerability, fixed across iOS, iPadOS, macOS, tvOS, watchOS, and visionOS, was assigned CVE-2026-84523.
I had also submitted multiple Kernel vulnerabilities. Apple listed my name alongside several other researchers in a general Kernel acknowledgment, without indicating whether any of the reports shared a root cause or concerned entirely separate vulnerabilities.
My ppp report was acknowledged separately in the iOS/iPadOS 27 and macOS Golden Gate 27 advisories.
CVE-2026-84523 - APFS
The fix is included in iOS 27 and iPadOS 27, iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27, macOS Tahoe 26.7, macOS Sequoia 15.8, tvOS 27, watchOS 27, and visionOS 27.
Additional Acknowledgments
Kernel
Apple included the Kernel acknowledgment in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27.
ppp

Apple included the ppp acknowledgment in iOS 27 and iPadOS 27 and macOS Golden Gate 27.
References
- Apple Security Releases
- About the security content of iOS 27 and iPadOS 27
- About the security content of iOS 26.7 and iPadOS 26.7
- About the security content of macOS Golden Gate 27
- About the security content of macOS Tahoe 26.7
- About the security content of macOS Sequoia 15.8
- About the security content of tvOS 27
- About the security content of watchOS 27
- About the security content of visionOS 27

