Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Apple operating systems contain a vulnerability in memory handling that allows a remote attacker to overwrite kernel memory or trigger an unexpected system termination, resulting in potential loss of data integrity and availability. The weakness is related to buffer overflows, use‑after‑free, and out‑of‑bounds writes, as reflected by the associated CWEs. The impact is severe, as kernel corruption could lead to privilege escalation or complete denial of service on the affected device.

Affected Systems

All Apple platforms—including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS—are affected if they run a release prior to the specified fixes. The vulnerability has been addressed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Risk and Exploitability

The CVSS score of 9.8 marks this as a very high‑severity issue, while the EPSS score of less than 1% indicates a low but non‑zero probability of exploitation. The flaw can be triggered by a remote user without special local privileges, making it a significant risk for exposed devices, although real‑world exploitation remains uncertain due to the low exploitation probability. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 3, 2026 at 16:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade iOS to 26.6 or later
  • Upgrade iPadOS to 26.6 or later
  • Upgrade macOS to Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6 or later
  • Upgrade tvOS, visionOS, and watchOS to 26.6 or later

Generated by OpenCVE AI on August 3, 2026 at 16:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Improper Memory Handling Allows Remote Kernel Corruption or System Termination

Sat, 01 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Improper Memory Handling Allows Remote Kernel Corruption or System Termination

Tue, 28 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-416
CWE-787
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T16:31:53.676Z

Reserved: 2026-05-01T22:46:27.821Z

Link: CVE-2026-43810

cve-icon Vulnrichment

Updated: 2026-07-28T16:03:02.793Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:04.140

Modified: 2026-07-29T20:37:53.773

Link: CVE-2026-43810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T16:45:03Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free

  • CWE-787

    Out-of-bounds Write