Description
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in how macOS processes environment variables can allow an application to trigger an unexpected system termination. The vulnerability stems from insufficient validation of these variables, leading to a crash that impacts the entire system rather than just the offending application. Such termination can disrupt user workflow and compromise service availability.

Affected Systems

Apple macOS is affected at versions before macOS Sequoia 15.7.8, macOS Sonoma 14.8.8 and macOS Tahoe 26.6. The fix is included in those releases, and earlier versions lack the improved validation.

Risk and Exploitability

The EPSS score indicates less than 1% exploitation probability, and the issue is not listed in CISA KEV, pointing to low publicly known exploitation activity. A CVSS score of 9.8 signals critical severity. The likely attack vector is local, requiring an application that sets or modifies environment variables to trigger a crash that terminates the entire system. With no known public exploits, the risk remains chiefly a destructive denial of service rather than a persistent compromise.

Generated by OpenCVE AI on August 3, 2026 at 15:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest macOS update that includes the fix (Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.6).
  • Restart or reload affected applications after the update to clear stale environment variables.
  • If possible, restrict or remove environment variables that are not required by the application to mitigate potential crashes.

Generated by OpenCVE AI on August 3, 2026 at 15:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Environment Variable Handling Causing System Termination

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Environment Variable Handling Causing System Termination
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T13:50:37.339Z

Reserved: 2026-05-01T22:46:27.820Z

Link: CVE-2026-43793

cve-icon Vulnrichment

Updated: 2026-07-28T13:50:26.871Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:02.793

Modified: 2026-07-28T19:47:57.223

Link: CVE-2026-43793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T16:00:07Z

Weaknesses
  • CWE-20

    Improper Input Validation