Junglewise Threat Intelligence

CVE-2026-43729: Apple Multiple Operating Systems Memory Corruption via Image Processing

CVE-2026-43729 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS Tahoe, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Apple has released security updates for iOS, iPadOS, macOS, tvOS, and visionOS to address a memory handling vulnerability. An attacker could exploit this flaw by tricking a user into opening or processing a specially crafted image. Successful exploitation could lead to memory corruption, potentially causing system instability or allowing unauthorized actions on the device.

Technical details

A memory corruption vulnerability exists in multiple Apple operating systems due to improper memory handling when processing image files. The flaw can be triggered by a maliciously crafted image, leading to process memory corruption. While the specific vulnerability class (e.g., buffer overflow) is not explicitly named, the impact is described as memory corruption resulting from image parsing. The attack vector is remote, typically requiring a user to download or view a malicious file. Apple has addressed the issue by improving memory handling in the affected components. Fixes are available in iOS/iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6.

Affected products

  • Apple iOS and iPadOS Before 26.6
  • Apple macOS Sequoia Before 15.7.8
  • Apple macOS Tahoe Before 26.6
  • Apple tvOS Before 26.6
  • Apple visionOS Before 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats