Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unexpected System Termination (Denial of Service)
Action: Update OS
AI Analysis

Impact

A use‑after‑free flaw was identified in several Apple operating systems that can be triggered when an application accesses memory that has been freed. The result is that the operating system terminates unexpectedly, leading to a denial‑of‑service condition. No evidence of arbitrary code execution or privilege escalation exists in the description, so the primary impact is loss of availability rather than confidentiality or integrity.

Affected Systems

Apple iOS, iPadOS, macOS, of the Apple operating system. The vulnerability is resolved in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6 and watchOS 26.6.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, while the EPSS score of <1% reflects a very low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is local, requiring the presence of a malicious or specially crafted application on the device. As a result, confidentiality and integrity risks are low; the primary risk remains a loss of availability through unexpected system termination.

Generated by OpenCVE AI on September 20, 2026 at 19:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6 or watchOS 26.6 to apply the updated memory management changes
  • Avoid installing applications from untrusted or unknown sources that may contain malformed memory usage patterns
  • Monitor Apple’s support pages and apply any new security updates as soon as they are released

Generated by OpenCVE AI on September 20, 2026 at 19:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Use‑after‑free causes unexpected system termination in Apple OS

Thu, 17 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Use‑after‑free causes unexpected system termination in Apple OS

Thu, 17 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Use-After‑Free Causing Unexpected System Termination on Apple OS

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Use-After‑Free Causing Unexpected System Termination on Apple OS
Weaknesses CWE-416

Tue, 15 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T18:22:20.749Z

Reserved: 2026-05-01T22:46:27.821Z

Link: CVE-2026-43808

cve-icon Vulnrichment

Updated: 2026-09-15T18:21:34.511Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:12.303

Modified: 2026-09-17T16:00:49.470

Link: CVE-2026-43808

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:15:03Z

Weaknesses