Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The vulnerability is an out-of-bounds write that was mitigated by adding stricter bounds checks. If executed, it can corrupt memory and cause the Apple operating systems—including macOS, iOS, and iPadOS—to terminate unexpectedly, effectively denying service to affected users. The weakness is a classic buffer overflow, specifically CWE-787.

Affected Systems

Apple's macOS, iOS, and iPadOS are affected. Versions before macOS Sequoia 15.7.8, macOS Tahoe 26.6, iOS 26.6, and iPadOS 26.6 contain the flaw. All deployments running these product releases are at risk until the supported security update is applied.

Risk and Exploitability

Exact exploitation data is not available; the EPSS score is <1% and the vulnerability is not in CISA's KEV catalog. The CVSS score of 9.8 indicates critical severity. The nature of the flaw suggests that an attacker would need to supply malformed data to a vulnerable application or launch a malicious app to trigger the crash. No public exploit proof‑of‑concept or active exploitation campaigns have been reported as of the data snapshot. The risk is primarily that a compromised or rogue application could bring the system down, but it does not enable remote code execution or data exfiltration.

Generated by OpenCVE AI on September 21, 2026 at 06:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install macOS Sequoia 15.7.8 or later, which contains the corrected bounds checks.
  • Install macOS Tahoe 26.6 or later, which contains the corrected bounds checks.
  • Install iOS 26.6 or later, which contains the corrected bounds checks.
  • Install iPadOS 26.6 or later, which contains the corrected bounds checks.
  • Restrict execution of untrusted applications until the system is updated.

Generated by OpenCVE AI on September 21, 2026 at 06:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Causing System Termination in macOS

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination. An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
References

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Causing System Termination in macOS

Tue, 04 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Causing Unexpected System Termination in macOS
Weaknesses CWE-119

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Causing Unexpected System Termination in macOS
Weaknesses CWE-119
CWE-787
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:48:36.899Z

Reserved: 2026-05-01T22:46:21.647Z

Link: CVE-2026-43748

cve-icon Vulnrichment

Updated: 2026-07-28T14:35:59.857Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:16:59.550

Modified: 2026-09-14T21:17:10.323

Link: CVE-2026-43748

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T06:45:10Z

Weaknesses