Junglewise Threat Intelligence

CVE-2026-43702: Apple iOS and macOS maliciously crafted video file memory corruption

CVE-2026-43702 · Severity: high · CVSS 7.8 · Published 2026-09-14

Technologies: Apple Tvos, Apple watchOS, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Apple's iOS, iPadOS, macOS, tvOS, and watchOS operating systems contain a flaw in video file processing that can be triggered by opening a specially-crafted video file. An attacker could exploit this to crash applications, disrupt service availability, or potentially corrupt device memory, affecting millions of users across iPhones, iPads, and Mac computers.

Technical details

The vulnerability exists in video file processing code across multiple Apple platforms. When a maliciously crafted video file is processed, improper memory handling can lead to unexpected application termination or corruption of process memory. The attack vector is local and requires user interaction (opening the malicious video). An attacker can achieve denial of service through app crashes and potential memory corruption. This issue was addressed with improved memory handling in the affected OS versions released July 27, 2026 (iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6) and later versions.

Affected products

  • Apple iOS before 26.6
  • Apple iPadOS before 26.6
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.6
  • Apple tvOS before 26.6
  • Apple watchOS before 26.6

Timeline

  • 2026-09-14: disclosed: CVE-2026-43702 disclosed
  • 2026-07-27: patched: Patched in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6 and later versions

References

Related threats