Description
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.
Published: 2026-09-14
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial‑of‑Service and Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

An integer overflow that can be triggered by a maliciously crafted file was discovered in macOS. The flaw allows an attacker to corrupt internal counters, causing the operating system to crash or unexpectedly terminate processes. (The corruption of internal counters is inferred rather than directly specified.) The overflow may also expose memory contents, potentially leaking sensitive data. This vulnerability is a classic integer overrun flaw (CWE‑190) that leads to loss of availability or accidental data exposure.

Affected Systems

The issue affects Apple macOS systems running versions earlier than macOS Golden Gate 27. The fix is implemented in macOS Golden Gate 27 and subsequent releases.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating that no widespread exploitation has been reported to date. The flaw is triggered by a crafted file to the system, so it is a local or file‑based attack vector (inferred). While no public exploit exists, the moderate severity of the integer overflow implies that the risk is non‑negligible if the vulnerable version is deployed.

Generated by OpenCVE AI on September 20, 2026 at 19:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the operating system to macOS Golden Gate 27 or later to obtain the patch that validates file inputs and eliminates the integer overflow
  • If an upgrade cannot be applied immediately, restrict the execution or parsing of files that may trigger the flaw, for example by disabling the affected feature or implementing sandboxing for untrusted data
  • Configure monitoring or alerting to detect and log unexpected crashes or abnormal file‑processing behavior that may indicate exploitation attempts

Generated by OpenCVE AI on September 20, 2026 at 19:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 20 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in macOS Causing Denial‑of‑Service and Possible Memory Disclosure

Wed, 16 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in macOS File Processing Causes Denial‑of‑Service and Potential Information Disclosure

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in macOS File Processing Causes Denial‑of‑Service and Potential Information Disclosure
Weaknesses CWE-190

Tue, 15 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T15:33:25.605Z

Reserved: 2026-05-01T22:46:27.819Z

Link: CVE-2026-43788

cve-icon Vulnrichment

Updated: 2026-09-15T15:33:11.828Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:11.490

Modified: 2026-09-15T19:31:45.393

Link: CVE-2026-43788

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:00:04Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound