Junglewise Threat Intelligence

CVE-2026-43654: Apple multiple operating systems kernel memory disclosure

CVE-2026-43654 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple Tvos, Apple watchOS, Apple Visionos, Apple macOS Sonoma, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in the core operating system kernel of Apple devices could allow a malicious application to access restricted system memory. This type of flaw can be used by attackers to bypass security protections or gather sensitive information about the system's internal operations. Users should update their iPhones, iPads, and Macs to the latest versions to ensure these protections are in place.

Technical details

A kernel-level vulnerability exists in multiple Apple operating systems due to improper memory handling. A local malicious application can exploit this flaw to disclose sensitive kernel memory, potentially aiding in the bypass of kernel address space layout randomization (KASLR) or other security mechanisms. The issue was addressed by Apple through improved memory handling and bounds checking across affected platforms. The vulnerability is reachable by any app running on the system without requiring special privileges beyond the ability to execute code.

Affected products

  • Apple iOS Before 18.7.9, before 26.5
  • Apple iPadOS Before 18.7.9, before 26.5
  • Apple macOS Sequoia Before 15.7.7
  • Apple macOS Sonoma Before 14.8.7
  • Apple macOS Tahoe Before 26.5
  • Apple tvOS Before 26.5
  • Apple visionOS Before 26.5
  • Apple watchOS Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats