Junglewise Threat Intelligence

CVE-2026-43656: Apple iOS and macOS out-of-bounds write in file parsing

CVE-2026-43656 · Severity: high · CVSS 7.3 · Published 2026-05-11

Technologies: Apple macOS Sonoma, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in Apple's operating systems (iOS, iPadOS, and macOS) could allow a malicious file to crash an application. By tricking a user into opening a specially crafted file, an attacker can cause the affected app to terminate unexpectedly. This impact is primarily focused on service availability and the stability of the device's software.

Technical details

An out-of-bounds write vulnerability exists in multiple Apple operating systems, including iOS, iPadOS, and macOS. The issue stems from insufficient input validation during the parsing of specially crafted files. An attacker can exploit this by providing a malicious file to a vulnerable application, leading to memory corruption and subsequent application termination (Denial of Service). Apple has addressed the root cause by improving input validation across affected versions, including iOS 18.7.9, iOS 26.5, and various macOS releases.

Affected products

  • Apple iOS 18.7.9, 26.5
  • Apple iPadOS 18.7.9, 26.5
  • Apple macOS Sequoia 15.7.7
  • Apple macOS Sonoma 14.8.7
  • Apple macOS Tahoe 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched

References

Related threats