Executive brief
Apple's iOS, iPadOS, macOS, tvOS, and watchOS operating systems contain a flaw in video file processing that can be triggered by opening a specially-crafted video file. An attacker could exploit this to crash applications, disrupt service availability, or potentially corrupt device memory, affecting millions of users across iPhones, iPads, and Mac computers.
Technical details
The vulnerability exists in video file processing code across multiple Apple platforms. When a maliciously crafted video file is processed, improper memory handling can lead to unexpected application termination or corruption of process memory. The attack vector is local and requires user interaction (opening the malicious video). An attacker can achieve denial of service through app crashes and potential memory corruption. This issue was addressed with improved memory handling in the affected OS versions released July 27, 2026 (iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6) and later versions.
Affected products
- Apple iOS before 26.6
- Apple iPadOS before 26.6
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.6
- Apple tvOS before 26.6
- Apple watchOS before 26.6
Timeline
- 2026-09-14: disclosed: CVE-2026-43702 disclosed
- 2026-07-27: patched: Patched in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6 and later versions