Junglewise Threat Intelligence

CVE-2026-43684: Apple iOS, iPadOS, and macOS use-after-free in kernel memory

CVE-2026-43684 · Severity: high · CVSS 7.8 · Published 2026-09-14

Technologies: Apple iPadOS, Apple macOS Sequoia, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

A use-after-free memory bug affects Apple's iOS, iPadOS, and macOS operating systems. An attacker can craft a malicious app or file that exploits this flaw to crash the system or corrupt kernel memory, potentially leading to data loss or system instability. This requires no special privileges but could impact any user running vulnerable OS versions.

Technical details

A use-after-free vulnerability in Apple's kernel memory management allows an app to reference memory that has already been freed. The vulnerability is triggered when processing maliciously crafted input, and the attack is local (requires the app to be installed and executed on the device). Exploitation can lead to unexpected system termination or kernel memory corruption. The fix improves memory management to prevent freed memory from being accessed. Patches are available in iOS 26.7, iPadOS 26.7, macOS Golden Gate 27, and macOS Sequoia 15.8.

Affected products

  • Apple iOS before 26.7
  • Apple iPadOS before 26.7
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8

Timeline

  • 2026-09-14: disclosed: CVE-2026-43684 disclosed alongside iOS 26.7, iPadOS 26.7, macOS Golden Gate 27 releases
  • 2026-09-14: patched: Fixed in iOS 26.7, iPadOS 26.7, macOS Golden Gate 27, and macOS Sequoia 15.8

References

Related threats