Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A use‑after‑free flaw in macOS memory handling can cause the operating system to crash when freed memory is accessed. This results in an may classified as CWE‑416, highlighting failure to protect memory after it has been freed.

Affected Systems

All Apple macOS releases before Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6 are vulnerable. Systems running these or earlier builds, regardless of service tier, lack the patch that secures the freed memory reference and therefore remain at risk.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% shows a very low current exploit probability. The vulnerability is not listed in CISA KEV, and no public exploits are known. Based on the description, it is inferred that the issue could be triggered by executing untrusted code or a manipulated application, either locally or remotely, that forces the freed memory to be accessed. Successful exploitation would lead to a system‑wide denial of service requiring recovery.

Generated by OpenCVE AI on September 20, 2026 at 20:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the macOS patch to Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6 to fix the use‑after‑free flaw (CWE‑416).
  • Limit execution of untrusted third‑party applications or run them in sandboxed environments until the update is applied, mitigating the risk of an attacker exploiting the freed memory reference.
  • Enable automatic macOS updates or regularly check for new releases so that future patches are applied promptly.

Generated by OpenCVE AI on September 20, 2026 at 20:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free Causing macOS System Crash

Wed, 16 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Allowing Unexpected System Termination in macOS

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Allowing Unexpected System Termination in macOS
Weaknesses CWE-416

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T16:40:18.853Z

Reserved: 2026-03-03T16:36:03.988Z

Link: CVE-2026-28933

cve-icon Vulnrichment

Updated: 2026-09-15T16:40:10.559Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:05.290

Modified: 2026-09-15T19:26:48.493

Link: CVE-2026-28933

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:15:04Z

Weaknesses