Description
The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
Published: 2026-09-14
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption leading to unexpected system termination
Action: Patch immediately
AI Analysis

Impact

A remote attacker can exploit improper memory handling in macOS kernel to corrupt kernel memory or terminate the operating system unexpectedly. The flaw is a classic buffer overflow and out‑of‑bounds write (CWE‑787) that can compromise system integrity and availability, potentially allowing further privileged malicious actions.

Affected Systems

Apple’s macOS is affected. The vulnerability exists in Golden Gate 27, Sequoia 15.8, and Tahoe 26.7. Users of any of these releases are vulnerable until they apply the fix in a newer release.

Risk and Exploitability

The CVSS score of 9.1 reflects a high severity. EPSS indicates a very low probability of exploitation (<1%). The vulnerability is not yet listed in CISA KEV. It is inferred that the attack vector is remote, likely requiring an ability to deliver crafted input that manipulates kernel memory, but no public exploit is documented.

Generated by OpenCVE AI on September 20, 2026 at 22:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade macOS to Golden Gate 27, Sequoia 15.8, or Tahoe 26.7, which include the memory handling fix
  • If an immediate upgrade is not possible, apply any vendor‑released security patches that address kernel memory handling
  • Continuously monitor system logs and use integrity‑checking tools to detect unexpected crashes or signs of memory corruption

Generated by OpenCVE AI on September 20, 2026 at 22:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title macOS Kernel Memory Corruption Vulnerability (Remote Exploit Possible)

Sun, 20 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Kernel memory corruption causing unexpected system termination in macOS
Weaknesses CWE-119
CWE-789

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Wed, 16 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Kernel memory corruption causing unexpected system termination in macOS
Weaknesses CWE-119
CWE-789

Tue, 15 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T16:58:41.367Z

Reserved: 2026-05-01T22:46:27.820Z

Link: CVE-2026-43790

cve-icon Vulnrichment

Updated: 2026-09-17T16:11:31.915Z

cve-icon NVD

Status : Modified

Published: 2026-09-14T21:17:11.703

Modified: 2026-09-17T17:16:41.237

Link: CVE-2026-43790

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:45:05Z

Weaknesses