Executive brief
Apple macOS contains a memory safety vulnerability that allows an application to read data beyond intended boundaries. Exploitation could cause unexpected application crashes or allow attackers to access sensitive data from the affected process's memory, potentially compromising user privacy or enabling further attacks.
Technical details
CVE-2026-43683 is an out-of-bounds read vulnerability in macOS that was addressed with improved bounds checking. The vulnerability exists in memory access routines, allowing an attacker to read beyond allocated memory boundaries. The attack requires running an application on the affected system; no network access is required. A malicious or compromised application can trigger this vulnerability to cause process termination or leak sensitive memory contents. The vulnerability is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched