Description
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in macOS memory handling can allow an application to cause the operating system to terminate unexpectedly or to write to kernel memory. The vulnerability could lead to a compromise of system integrity and stability, potentially allowing an attacker to execute arbitrary code with kernel privileges if they have the ability to trigger the flaw. The description emphasizes kernel memory access and system crashes, indicating a severe impact on confidentiality, integrity, and availability.

Affected Systems

Apple macOS systems are susceptible. The issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Devices running earlier releases of these macOS versions are therefore vulnerable.

Risk and Exploitability

The CVSS score is 9.8, indicating critical severity. The EPSS score is less than 1%, suggesting a low probability of exploitation at this time. The vulnerability is not listed in CISA KEV. Based on the description, the attack vector is likely local or requires an application to be executed with user privileges that can invoke the vulnerable memory handling code. Exploitation would involve triggering the fault that results in a system crash or a kernel memory write, potentially allowing an attacker to gain kernel privilege if successful.

Generated by OpenCVE AI on August 3, 2026 at 16:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest macOS update (sequoia 15.7.8, sonoma 14.8.8, or tahoe 26.6) to contain the flaw
  • Restrict or remove untrusted applications that could trigger the memory handling code from executing with elevated privileges
  • Enable or verify System Integrity Protection to prevent unauthorized kernel memory modifications

Generated by OpenCVE AI on August 3, 2026 at 16:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Kernel Memory Write/Crash Vulnerability in macOS

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Kernel Memory Write/Crash Vulnerability in macOS
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:19:55.911Z

Reserved: 2026-05-01T22:46:21.642Z

Link: CVE-2026-43694

cve-icon Vulnrichment

Updated: 2026-07-28T14:19:44.511Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:16:53.273

Modified: 2026-07-29T15:46:12.623

Link: CVE-2026-43694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T16:15:03Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer