Junglewise Threat Intelligence

CVE-2026-43668: Apple multiple operating systems use after free in mDNSResponder

CVE-2026-43668 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple Tvos, Apple watchOS, Apple Visionos, Apple macOS Sonoma, Apple iPadOS. Vendors: Apple.

Executive brief

A memory management vulnerability has been identified in various Apple operating systems, including iOS, macOS, and watchOS. This flaw could allow a remote attacker to cause a device to crash or potentially corrupt sensitive system memory. Exploitation of this issue could lead to service disruptions or unauthorized access to system-level data.

Technical details

A use-after-free vulnerability exists in multiple Apple operating systems due to improper memory management. A remote attacker can exploit this flaw to cause unexpected system termination (denial of service) or corrupt kernel memory. The vulnerability was addressed by improving memory management logic across affected platforms. The issue impacts a wide range of Apple products, including iPhones, iPads, Macs, Apple TV, Apple Watch, and Vision Pro. Patches are available in iOS 18.7.9, iOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, and corresponding versions for other platforms.

Affected products

  • Apple iOS Before 18.7.9, before 26.5
  • Apple iPadOS Before 18.7.9, before 26.5
  • Apple macOS Sequoia Before 15.7.7
  • Apple macOS Sonoma Before 14.8.7
  • Apple macOS Tahoe Before 26.5
  • Apple tvOS Before 26.5
  • Apple visionOS Before 26.5
  • Apple watchOS Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats