Junglewise Threat Intelligence

CVE-2026-43697: Apple macOS out-of-bounds read in 3D file processing

CVE-2026-43697 · Severity: high · CVSS 7.1 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

macOS is the operating system used on Apple computers to run business and personal applications. A vulnerability in how macOS processes 3D files could allow an attacker to read data beyond allocated memory boundaries, potentially exposing sensitive information or causing the system to crash. This issue affects recent versions of macOS across multiple models.

Technical details

An out-of-bounds read vulnerability exists in macOS's handling of 3D files, where the bounds checking logic fails to properly validate memory access during file processing. The vulnerability is triggered when a user or application processes a maliciously crafted 3D file. The attack requires no special privileges or network access—simply processing the file can trigger the issue. An attacker can craft a malicious 3D file that, when opened, reads memory outside the intended bounds, potentially disclosing sensitive data from adjacent memory regions or causing a denial of service. The issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats