Description
This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote attacker may be able to cause a denial of service.
Published: 2026-07-27
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper input validation (CWE‑20) that allows a remote attacker to supply specially crafted data and trigger a crash, resulting in a denial of service of the operating system. The flaw is located in parts of macOS that process external input, and when the malformed data is processed the system becomes unresponsive or restarts. The impact is a loss of availability for the affected device and any services it hosts.

Affected Systems

Apple’s macOS is affected, specifically any installation that does not include the latest fixes. The vulnerability has been addressed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6; any earlier versions may be impacted.

Risk and Exploitability

An EPSS score of < 1% and a CVSS score of 7.5 are provided, indicating moderate severity but a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The flaw allows a remote attacker to send malicious input that triggers a denial of service, likely over the network or via user‑supplied data. No widespread attacks have been observed, but caution is advised.

Generated by OpenCVE AI on August 4, 2026 at 13:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest macOS update that includes the fix (Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6).
  • If an update cannot be applied immediately, reduce exposure by restricting network access to services that receive untrusted input, such as disabling remote desktop or file sharing, to mitigate the improper input validation flaw (CWE‑20).
  • Monitor system logs for unexpected crashes or restarts, investigate anomalies, and consider disabling or updating third‑party applications that may invoke vulnerable components.

Generated by OpenCVE AI on August 4, 2026 at 13:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Improper Input Validation in macOS

Thu, 30 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Improper Input Validation in macOS

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote attacker may be able to cause a denial of service.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:52:30.889Z

Reserved: 2026-05-01T22:46:27.819Z

Link: CVE-2026-43777

cve-icon Vulnrichment

Updated: 2026-07-28T14:52:26.923Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:02.077

Modified: 2026-07-28T17:59:08.170

Link: CVE-2026-43777

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:15:03Z

Weaknesses
  • CWE-20

    Improper Input Validation