Junglewise Threat Intelligence

CVE-2026-43733: Apple iOS and macOS memory corruption in image processing

CVE-2026-43733 · Severity: info · Published 2026-07-27

Technologies: Apple macOS Tahoe, Apple iPadOS. Vendors: Apple.

Executive brief

Apple has released security updates for iOS, iPadOS, and macOS to address a memory handling vulnerability. An attacker could exploit this by tricking a user into opening a specially crafted image file, which could lead to memory corruption. This type of flaw can potentially be used to crash applications or gain unauthorized access to system resources.

Technical details

A memory corruption vulnerability exists in Apple's operating systems (iOS, iPadOS, and macOS) due to improper memory handling when processing image files. The flaw is triggered when the system parses a maliciously crafted image, potentially leading to process memory corruption. The attack vector is local, typically requiring a user to download or open a malicious file. Apple has addressed the issue by improving memory handling in the affected components. Patches are available in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, and macOS Tahoe 26.6.

Affected products

  • Apple iOS before 26.6
  • Apple iPadOS before 26.6
  • Apple macOS Sequoia before 15.7.8
  • Apple macOS Tahoe before 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats