Description
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted asset catalog may result in disclosure of process memory.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malformed asset catalog can trigger improper memory handling in macOS, leading to the exposure of process memory contents. This information disclosure could allow an attacker to gain unauthorized access to sensitive data residing in memory. The vulnerability is an example of improper internal resource handling, where unvalidated input causes memory leaking. The primary impact is confidentiality compromise.

Affected Systems

Apple macOS products are affected, specifically versions prior to macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8. The vulnerable code path processes asset catalogs, which are used to bundle resources for applications. Users running these operating system releases are potentially exposed to memory disclosure if they process maliciously crafted catalogs.

Risk and Exploitability

With a CVSS score of 5.5, the vulnerability represents moderate severity. The EPSS score is below 1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is delivery of a malicious asset catalog to macOS or a privileged application; exploitation requires the ability to supply a crafted catalog to the vulnerable code path. Once processed, memory contents may be read and extracted by the attacker. The risk remains moderate until a patch is applied.

Generated by OpenCVE AI on August 5, 2026 at 00:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update macOS to at least Sequoia 15.7.8 or Sonoma 14.8.8 to receive the fixed memory handling code
  • Avoid loading or processing untrusted asset catalogs until the patch is applied
  • Execute security hardening practices such as restricting the source of catalog files and ensuring only signed or verified resources are used

Generated by OpenCVE AI on August 5, 2026 at 00:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Improper Memory Handling in macOS Asset Catalogs Leading to Process Memory Disclosure

Tue, 04 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Improper Memory Handling in macOS Asset Catalogs Leading to Process Memory Disclosure
Weaknesses CWE-200

Sun, 02 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Malicious Asset Catalog May Cause Process Memory Disclosure on macOS

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Malicious Asset Catalog May Cause Process Memory Disclosure on macOS
Weaknesses CWE-125
CWE-200
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted asset catalog may result in disclosure of process memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:56:55.407Z

Reserved: 2026-05-01T22:46:21.646Z

Link: CVE-2026-43738

cve-icon Vulnrichment

Updated: 2026-07-28T14:55:57.984Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:16:58.420

Modified: 2026-07-28T19:32:04.280

Link: CVE-2026-43738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T00:30:05Z

Weaknesses