Description
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected process termination or disclose process memory.
Published: 2026-09-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure and denial of service
Action: Immediate patch
AI Analysis

Impact

An out-of-bounds read identified in Apple macOS components was mitigated through improved bounds checking. Triggering the flaw can cause a process to terminate unexpectedly or expose that process’s memory contents. The weakness corresponds to CWE-125, a bounds-checking error that can lead to information disclosure.

Affected Systems

Apple macOS users running releases prior to macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 are affected. These versions contain the vulnerable code; later releases are not impacted.

Risk and Exploitability

The EPSS score is < 1 % and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score is 7.1, indicating a high severity that can result in confidentiality compromise and denial of service. The likely attack vector requires the vulnerable code to execute within the target process, implying a local or application-level exploitation scenario. Given the low exploitation probability, widespread exploitation remains uncertain.

Generated by OpenCVE AI on September 20, 2026 at 21:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the macOS updates that fix the out‑of‑bounds read: upgrade to macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 or later.
  • If an upgrade is not immediately possible, restrict execution of applications that invoke the vulnerable code and monitor the associated processes for abnormal crashes.
  • Keep the system’s security updates current and review Apple’s advisories for any related guidance.

Generated by OpenCVE AI on September 20, 2026 at 21:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in macOS Causing Process Termination and Memory Disclosure

Fri, 18 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Causing Potential Memory Disclosure and Process Termination
Weaknesses CWE-200
CWE-788

Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Causing Potential Memory Disclosure and Process Termination
Weaknesses CWE-200
CWE-788

Mon, 14 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected process termination or disclose process memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T15:53:23.146Z

Reserved: 2026-05-01T22:46:21.641Z

Link: CVE-2026-43683

cve-icon Vulnrichment

Updated: 2026-09-17T15:53:12.724Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:07.123

Modified: 2026-09-18T14:40:16.130

Link: CVE-2026-43683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:15:04Z

Weaknesses