Executive brief
A memory handling flaw in macOS could allow a remote attacker to crash the system or corrupt kernel memory, leading to potential system instability or data loss. This affects multiple versions of Apple's operating system across Intel and Apple silicon Macs. The vulnerability requires no user interaction and is accessed over the network.
Technical details
CVE-2026-43790 is an out-of-bounds write or memory corruption vulnerability in the macOS kernel or a core system component. The vulnerability allows a remote attacker to trigger unexpected kernel termination or corrupt kernel memory through a maliciously crafted input or request. The fix involves improved memory handling and bounds checking. The vulnerability affects macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, which were released on September 14, 2026.
Affected products
- Apple macOS Golden Gate 27
- Apple macOS Sequoia 15.8
- Apple macOS Tahoe 26.7
Timeline
- 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7
- 2026-09-14: disclosed