2026-07-27 20:14CVE-2026-43803apple
PUBLISHED5.2

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to cause unexpected system termination.

Problem type

  • A remote attacker may be able to cause unexpected system termination

Affected products

Apple

iOS and iPadOS

< 26.6 - AFFECTED

macOS

< 14.8.8 - AFFECTED

< 15.7.8 - AFFECTED

< 26.6 - AFFECTED

tvOS

< 26.6 - AFFECTED

visionOS

< 26.6 - AFFECTED

watchOS

< 26.6 - AFFECTED

References

GitHub Security Advisories

GHSA-mv2g-98jj-rj6f

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in...

https://github.com/advisories/GHSA-mv2g-98jj-rj6f

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to cause unexpected system termination.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-43803
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-43803",
    "assignerOrgId": "286789f9-fbc2-4510-9f9a-43facdede74c",
    "assignerShortName": "apple",
    "dateUpdated": "2026-07-28T13:48:30.500Z",
    "dateReserved": "2026-05-01T22:46:27.821Z",
    "datePublished": "2026-07-27T20:14:02.024Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "286789f9-fbc2-4510-9f9a-43facdede74c",
        "shortName": "apple",
        "dateUpdated": "2026-07-27T20:14:02.024Z"
      },
      "descriptions": [
        {
          "lang": "en",
          "value": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to cause unexpected system termination."
        }
      ],
      "affected": [
        {
          "vendor": "Apple",
          "product": "iOS and iPadOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "macOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "14.8.8"
            },
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "15.7.8"
            },
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "tvOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "visionOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "watchOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "A remote attacker may be able to cause unexpected system termination"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066"
        },
        {
          "url": "https://support.apple.com/en-us/128067"
        },
        {
          "url": "https://support.apple.com/en-us/128068"
        },
        {
          "url": "https://support.apple.com/en-us/128069"
        },
        {
          "url": "https://support.apple.com/en-us/128070"
        },
        {
          "url": "https://support.apple.com/en-us/128071"
        },
        {
          "url": "https://support.apple.com/en-us/128072"
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2026-07-28T13:48:30.500Z"
        },
        "title": "CISA ADP Vulnrichment",
        "problemTypes": [
          {
            "descriptions": [
              {
                "lang": "en",
                "description": "CWE-787 Out-of-bounds Write",
                "cweId": "CWE-787",
                "type": "CWE"
              }
            ]
          }
        ],
        "metrics": [
          {
            "cvssV3_1": {
              "version": "3.1",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "attackVector": "NETWORK",
              "attackComplexity": "LOW",
              "privilegesRequired": "NONE",
              "userInteraction": "NONE",
              "scope": "UNCHANGED",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "availabilityImpact": "HIGH",
              "baseScore": 9.8,
              "baseSeverity": "CRITICAL"
            }
          },
          {}
        ]
      }
    ]
  }
}