Executive brief
Apple's AirDrop feature, which enables wireless file sharing between Apple devices, contains a logic flaw that can be triggered by an attacker positioned on the same network. An attacker can send specially crafted network packets to cause AirDrop to crash, disrupting file sharing capabilities for affected users. The issue requires network proximity but does not require authentication or user interaction beyond normal device operation.
Technical details
A reachable assertion vulnerability was identified in the AirDrop component. The vulnerability stems from insufficient input validation that allows crafted network packets to trigger an assertion failure, causing denial of service. The attack vector is network-based and requires the attacker to be in a privileged network position (same network segment). An attacker cannot gain code execution or access sensitive data, but can reliably cause AirDrop to crash. The vulnerability has been fixed in iOS 18.7.10, iPadOS 18.7.10, iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, and watchOS 26.5 through improved input validation.
Affected products
- Apple iOS before 18.7.10 and before 26.5
- Apple iPadOS before 18.7.10 and before 26.5
- Apple macOS Tahoe before 26.5
- Apple visionOS before 26.5
- Apple watchOS before 26.5
Timeline
- 2026-08-17: disclosed: CVE-2026-43667 published
- 2026-05-11: patched: Fixed in iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5; also iOS 18.7.10, iPadOS 18.7.10