2026-07-27 20:13CVE-2026-43750apple
PUBLISHED5.2

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

Problem type

  • An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges

Affected products

Apple

macOS

< 14.8.8 - AFFECTED

< 15.7.8 - AFFECTED

< 26.6 - AFFECTED

References

GitHub Security Advisories

GHSA-g5rh-q4ff-2c5x

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS...

https://github.com/advisories/GHSA-g5rh-q4ff-2c5x

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-43750
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-43750",
    "assignerOrgId": "286789f9-fbc2-4510-9f9a-43facdede74c",
    "assignerShortName": "apple",
    "dateUpdated": "2026-07-28T14:07:10.843Z",
    "dateReserved": "2026-05-01T22:46:21.647Z",
    "datePublished": "2026-07-27T20:13:47.889Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "286789f9-fbc2-4510-9f9a-43facdede74c",
        "shortName": "apple",
        "dateUpdated": "2026-07-27T20:13:47.889Z"
      },
      "descriptions": [
        {
          "lang": "en",
          "value": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges."
        }
      ],
      "affected": [
        {
          "vendor": "Apple",
          "product": "macOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "14.8.8"
            },
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "15.7.8"
            },
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067"
        },
        {
          "url": "https://support.apple.com/en-us/128071"
        },
        {
          "url": "https://support.apple.com/en-us/128072"
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2026-07-28T14:07:10.843Z"
        },
        "title": "CISA ADP Vulnrichment",
        "problemTypes": [
          {
            "descriptions": [
              {
                "lang": "en",
                "description": "CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
                "cweId": "CWE-120",
                "type": "CWE"
              }
            ]
          }
        ],
        "metrics": [
          {
            "cvssV3_1": {
              "version": "3.1",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "attackVector": "NETWORK",
              "attackComplexity": "LOW",
              "privilegesRequired": "NONE",
              "userInteraction": "NONE",
              "scope": "UNCHANGED",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "availabilityImpact": "HIGH",
              "baseScore": 9.8,
              "baseSeverity": "CRITICAL"
            }
          },
          {}
        ]
      }
    ]
  }
}