Description
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. Processing a maliciously crafted file may lead to unexpected app termination.
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The flaw is a memory corruption vulnerability that occurs when Apple iOS, iPadOS, or macOS processes a specially crafted file. The resulting corruption can crash the application that parses the file, leading to an unexpected termination. The weakness is classified as CWE‑1021 and does not grant code execution or privilege escalation, but it can interrupt normal application operation and cause availability loss.

Affected Systems

Apple iOS, iPadOS, and macOS devices running versions prior to 27 (iOS 27, iPadOS 27, and macOS Golden Gate 27) are affected. The fix was introduced in the 27 release, so any device still using an earlier OS is vulnerable to this memory corruption issue.

Risk and Exploitability

The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a very low current exploitation probability. The CVSS score of 7.8 reflects a high severity for a denial‑of‑service flaw. The likely attack vector is the delivery of a malicious file to the device—e.g., via email attachment, download, or removable media—and its subsequent processing by an application that lacks additional safeguards. Because the flaw does not provide code execution, the primary risk is to application availability rather than to broader system compromise.

Generated by OpenCVE AI on September 20, 2026 at 21:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade all affected devices to iOS 27, iPadOS 27, or macOS Golden Gate 27 to apply the input validation fix.
  • Avoid opening or executing files from untrusted sources until the update is applied, especially email attachments, downloaded content, or media from unknown devices.
  • Enable and enforce application sandboxing or file‑execution restrictions to limit the impact of any remaining vulnerabilities, and monitor for unexpected application crashes.

Generated by OpenCVE AI on September 20, 2026 at 21:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Apple OSes Vulnerable to Memory Corruption Leading to Application Crash via Malicious Files

Thu, 17 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1021
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Memory Corruption Exploitable Through Malicious File Leading to App Crash
Weaknesses CWE-120
CWE-787

Tue, 15 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Title Memory Corruption Exploitable Through Malicious File Leading to App Crash
Weaknesses CWE-120
CWE-787

Tue, 15 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. Processing a maliciously crafted file may lead to unexpected app termination.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T13:56:04.230Z

Reserved: 2026-05-01T22:46:21.642Z

Link: CVE-2026-43688

cve-icon Vulnrichment

Updated: 2026-09-16T13:55:13.379Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:08.133

Modified: 2026-09-17T18:41:43.723

Link: CVE-2026-43688

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:45:04Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames