Description
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds read has been addressed via improved bounds checking, but the flaw can still lead to an unexpected system termination when triggered by a malicious app. This results in a denial of service by crashing the operating system. The bug does not expose or alter sensitive data, so its threat to confidentiality or integrity is minimal.

Affected Systems

Apple iOS, iPadOS, macOS (Tahoe), tvOS, visionOS, and watchOS versions older than 26.6 are affected. Each platform received a fix in 26.6, the same release used to remediate the issue.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity level. The EPSS score of less than 1 % suggests an exceptionally low probability of exploitation under current circumstances, and the vulnerability is not listed in CISA’s KEV catalog. The most probable attack vector is a malicious application supplying crafted input to the vulnerable component, which can induce the crash once the bounds check fails. No public exploit is documented in the available data, so the actual risk hinges on the likelihood that an adversary can deliver such malicious input.

Generated by OpenCVE AI on August 5, 2026 at 01:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all Apple operating systems to version 26.6 or later (iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6).
  • Enable automatic system updates to receive future security fixes promptly.
  • Review installed third‑party applications for potential memory‑safety issues and remove or update any that may contain similar memory‑corruption patterns.

Generated by OpenCVE AI on August 5, 2026 at 01:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Causing Unexpected System Termination

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Causing System Crash
Weaknesses CWE-120

Thu, 30 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Causing System Crash
Weaknesses CWE-120

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T17:55:13.418Z

Reserved: 2026-05-01T22:46:27.822Z

Link: CVE-2026-43817

cve-icon Vulnrichment

Updated: 2026-07-28T17:42:43.144Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:04.720

Modified: 2026-07-29T20:36:38.780

Link: CVE-2026-43817

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:00:12Z

Weaknesses