Description
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted 3D file may lead to an out-of-bounds read.
Published: 2026-09-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via Vulnerable 3D File Processing
Action: Patch
AI Analysis

Impact

This vulnerability is an out-of-bounds read caused by insufficient bounds checking when processing a maliciously crafted 3D file. The flaw allows an attacker to read memory locations beyond the intended buffer, potentially exposing sensitive data stored in memory. The weakness is a classic example of improper memory bounds validation, giving the attacker the chance to retrieve data that should remain private.

Affected Systems

Apple macOS is affected. The issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Users running earlier releases of these operating systems should update.

Risk and Exploitability

The CVSS base score is 4.3. EPSS score is < 1% and the vulnerability has not been listed in CISA KEV. Because the attack vector requires the user to open a crafted 3D file, local privilege or user interaction is likely needed, lowering the likelihood of exploitation compared, the potential to leak arbitrary memory contents warrants timely remediation.

Generated by OpenCVE AI on September 20, 2026 at 20:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to macOS Golden Gate 27 or later, macOS Sequoia 15.8 or later, or macOS Tahoe 26.7 or later to receive the patch that adds proper bounds checking.
  • If an upgrade is not immediately possible, avoid opening or processing untrusted 3D files until a fix is applied.
  • Check Apple support pages for any additional guidance or temporary mitigations related to 3D file handling.

Generated by OpenCVE AI on September 20, 2026 at 20:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read via Malicious 3D File Processing in macOS

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Thu, 17 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read via Malicious 3D File Processing in macOS
Weaknesses CWE-119

Wed, 16 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in 3D File Processing on macOS
Weaknesses CWE-119

Tue, 15 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in 3D File Processing on macOS
Weaknesses CWE-119

Mon, 14 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted 3D file may lead to an out-of-bounds read.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T17:13:57.465Z

Reserved: 2026-05-01T22:46:21.643Z

Link: CVE-2026-43697

cve-icon Vulnrichment

Updated: 2026-09-17T17:13:47.359Z

cve-icon NVD

Status : Modified

Published: 2026-09-14T21:17:08.863

Modified: 2026-09-17T18:16:42.037

Link: CVE-2026-43697

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:15:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-125

    Out-of-bounds Read