Junglewise Threat Intelligence

CVE-2026-43655: Apple IOSurfaceAccelerator out-of-bounds read in multiple OSs

CVE-2026-43655 · Severity: high · CVSS 7.3 · Published 2026-05-11

Technologies: Apple Tvos, Apple macOS, Apple Iphone Os, Apple watchOS, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in Apple's operating systems could allow a malicious application to crash the device or access restricted system memory. This affects iPhones, iPads, Macs, Apple TVs, and Apple Watches. An exploit could lead to a complete system restart or the exposure of sensitive internal system data.

Technical details

An out-of-bounds read vulnerability exists in the IOSurfaceAccelerator component of multiple Apple operating systems. The flaw is caused by insufficient bounds checking when processing certain inputs. A local malicious application can exploit this vulnerability to trigger a kernel-level out-of-bounds read, potentially leading to a denial-of-service (system crash) or the disclosure of sensitive kernel memory. Apple has addressed the issue by improving bounds checking in iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, and watchOS 26.5.

Affected products

  • Apple iOS Before 26.5
  • Apple iPadOS Before 26.5
  • Apple macOS Tahoe Before 26.5
  • Apple tvOS Before 26.5
  • Apple watchOS Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats