Junglewise Threat Intelligence

CVE-2026-43774: Apple macOS out-of-bounds read sensitive data exposure

CVE-2026-43774 · Severity: info · Published 2026-07-27

Technologies: Apple macOS Sequoia. Vendors: Apple.

Executive brief

A security vulnerability in macOS could allow a malicious application to access sensitive user data. This issue affects several versions of the Mac operating system, including Sequoia, Sonoma, and Tahoe. Apple has released software updates to address this flaw by improving how the system validates data boundaries.

Technical details

An out-of-bounds read vulnerability exists in macOS due to insufficient bounds checking. A malicious application installed on the system could exploit this flaw to read memory outside of its intended buffer, potentially leading to the disclosure of sensitive user information. The vulnerability is triggered when the system processes specifically crafted data without adequate validation. Apple addressed the root cause by implementing improved bounds checking in the affected components. The fix is available in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.

Affected products

  • Apple macOS Sequoia before 15.7.8
  • Apple macOS Sonoma before 14.8.8
  • Apple macOS Tahoe before 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats