Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted asset catalog may result in disclosure of process memory.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Processing a maliciously crafted asset catalog can trigger improper memory handling in macOS, iOS, and iPadOS, leading to disclosure of process memory. The vulnerability originates from an improper handling of memory buffers (CWE‑125) during asset catalog parsing. If an attacker supplies a specially crafted catalog, the system may read beyond the intended memory region and reveal confidential data. The primary impact is the potential compromise of sensitive information stored in process memory.

Affected Systems

Apple iOS, iPadOS and macOS products are affected, specifically versions prior to iOS 18.7.10, iPadOS 18.7.10, macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8. The vulnerable code path processes asset catalogs, which are used to bundle resources for applications. Users running these operating system releases are potentially exposed to memory disclosure if they process maliciously crafted catalogs.

Risk and Exploitability

With a CVSS score of 5.5, the vulnerability represents moderate severity. The EPSS score is below 1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is delivery of a malicious asset catalog to macOS or a privileged application; exploitation requires the ability to supply a crafted catalog to the vulnerable code path. Once processed, memory contents may be read and extracted by the attacker. The risk remains moderate until a patch is applied.

Generated by OpenCVE AI on August 17, 2026 at 23:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update macOS to at least Sequoia 15.7.8 or Sonoma 14.8.8 to receive the fixed memory handling code
  • Update iOS to 18.7.10 and iPadOS to 18.7.10 to receive the fixed memory handling code
  • Avoid loading or processing untrusted asset catalogs until the patch is applied
  • Execute security hardening practices such as restricting the source of catalog files and ensuring only signed or verified resources are used

Generated by OpenCVE AI on August 17, 2026 at 23:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Asset Catalog Memory Disclosure Vulnerability in macOS and iOS

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted asset catalog may result in disclosure of process memory. The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted asset catalog may result in disclosure of process memory.
References

Wed, 05 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Improper Memory Handling in macOS Asset Catalogs Leading to Process Memory Disclosure

Tue, 04 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Improper Memory Handling in macOS Asset Catalogs Leading to Process Memory Disclosure
Weaknesses CWE-200

Sun, 02 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Malicious Asset Catalog May Cause Process Memory Disclosure on macOS

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Malicious Asset Catalog May Cause Process Memory Disclosure on macOS
Weaknesses CWE-125
CWE-200
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted asset catalog may result in disclosure of process memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:29:47.277Z

Reserved: 2026-05-01T22:46:21.646Z

Link: CVE-2026-43738

cve-icon Vulnrichment

Updated: 2026-07-28T14:55:57.984Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:16:58.420

Modified: 2026-08-17T22:17:10.017

Link: CVE-2026-43738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T23:15:04Z

Weaknesses