Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, iOS 26.7 and iPadOS 26.7, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7, tvOS 26.6, watchOS 26.6. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption / Application Crash
Action: Apply Patch
AI Analysis

Impact

Improper handling of video decoding causes memory corruption or unexpected application termination when a malicious video file is processed. The vulnerability is a buffer handling fault (CWE‑119) and results in corrupt process memory but does not provide a documented mechanism for arbitrary code execution or remote exploitation.

Affected Systems

Apple iOS 26.6 and 26.7, iPadOS 26.6 and 26.7, macOS Sequoia 15.8, mac Tahoe 26.6 and 26.7, tvOS 26.6, and watchOS 26.6 are affected. Versions newer than those listed contain the fix.

Risk and Exploitability

The CVSS score of 7.8 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. It is triggered by a local, user‑controlled input—a malicious video file—so the most likely attack vector involves a social‑engineering scenario where a user opens a hostile file. Exploitation leads to memory corruption and application crash or unstable behavior, but there is no evidence of remote or arbitrary code execution.

Generated by OpenCVE AI on September 20, 2026 at 21:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update all Apple devices to the latest OS version that incorporates the fix (iOS 26.6 / 26.7, iPadOS 26.6 / 26.7, macOS Sequoia 15.8, macOS Tahoe 26.6 / 26.7, tvOS 26.6 and newer, watchOS 26.6).
  • Remove or quarantine any maliciously crafted video files from the device or shared drives until verified safe.
  • Configure the device or application to block or disable video playback from untrusted sources, such as external SD cards or downloads from unknown origins.

Generated by OpenCVE AI on September 20, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Improper Video Decoding Causes Memory Corruption and Application Crashes

Thu, 17 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Unexpected App Termination or Memory Corruption via Malicious Video Processing
Weaknesses CWE-119

Tue, 15 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Unexpected App Termination or Memory Corruption via Malicious Video Processing
Weaknesses CWE-119

Tue, 15 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, iOS 26.7 and iPadOS 26.7, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7, tvOS 26.6, watchOS 26.6. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T14:16:35.892Z

Reserved: 2026-05-01T22:46:21.643Z

Link: CVE-2026-43702

cve-icon Vulnrichment

Updated: 2026-09-16T14:16:22.723Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:09.163

Modified: 2026-09-17T18:43:13.970

Link: CVE-2026-43702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:00:09Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer