Junglewise Threat Intelligence

CVE-2026-43738: Apple macOS information disclosure in asset catalog processing

CVE-2026-43738 · Severity: info · Published 2026-07-27

Technologies: Apple macOS Sonoma. Vendors: Apple.

Executive brief

A security vulnerability in macOS could allow a malicious file to leak sensitive information from the computer's memory. This occurs when the system processes a specially crafted asset catalog file, which is a common format used by applications to store images and icons. An attacker could use this to gain access to private data that should normally be protected by the operating system.

Technical details

An information disclosure vulnerability exists in macOS Sequoia and Sonoma due to improper memory handling when processing asset catalogs. By enticing a user to open or process a maliciously crafted asset catalog file, an attacker can trigger an out-of-bounds read or similar memory mismanagement, resulting in the disclosure of process memory. The issue was addressed by Apple through improved memory handling in macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8. Exploitation typically requires local access or user interaction to process the malicious file.

Affected products

  • Apple macOS Sequoia before 15.7.8
  • Apple macOS Sonoma before 14.8.8

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats