Junglewise Threat Intelligence

CVE-2026-43780: Apple multiple operating systems integer overflow in texture processing

CVE-2026-43780 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in Apple's operating systems could allow a malicious file to crash applications. This occurs when the system processes a specially crafted image texture, potentially leading to service disruptions or app instability on iPhones, Macs, and other Apple devices. Users should update to the latest software versions to resolve this issue.

Technical details

An integer overflow vulnerability exists in multiple Apple operating systems, including iOS, macOS, and watchOS. The flaw is triggered when the system processes a maliciously crafted texture file, which lacks proper input validation. An attacker could exploit this by providing a specially crafted image or media file that, when rendered or processed by an application, causes an integer overflow and subsequent application crash (denial of service). Apple addressed the issue by improving input validation across affected components. Fixed versions include iOS 26.6, macOS Sequoia 15.7.8, and macOS Sonoma 14.8.8.

Affected products

  • Apple iOS and iPadOS < 26.6
  • Apple macOS Sequoia < 15.7.8
  • Apple macOS Sonoma < 14.8.8
  • Apple macOS Tahoe < 26.6
  • Apple tvOS < 26.6
  • Apple visionOS < 26.6
  • Apple watchOS < 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats