Junglewise Threat Intelligence

CVE-2025-43236: Apple macOS type confusion memory handling issue

CVE-2025-43236 · Severity: low · CVSS 3.3 · Published 2026-04-02

Technologies: Apple macOS Sonoma, Apple macOS Ventura. Vendors: Apple.

Executive brief

A memory handling issue in macOS could allow an attacker to cause applications to crash unexpectedly. This affects users running older versions of macOS Sequoia, Sonoma, and Ventura. While the risk to data privacy is low, it can disrupt normal operations by causing software instability.

Technical details

A type confusion vulnerability (CWE-843) exists in macOS due to improper memory handling when processing certain resources. An attacker can exploit this flaw to cause a denial-of-service condition via unexpected application termination. The attack requires local access and typically involves some level of user interaction. Apple has addressed this issue by improving memory handling logic in macOS Sequoia 15.6, macOS Sonoma 14.7.7, and macOS Ventura 13.7.7.

Affected products

  • Apple macOS Sequoia before 15.6
  • Apple macOS Sonoma before 14.7.7
  • Apple macOS Ventura before 13.7.7

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory
  • 2026-04-02: patched

References

Related threats