Junglewise Threat Intelligence

CVE-2026-43807: Apple multiple operating systems buffer overflow via malicious accessory

CVE-2026-43807 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability affects various Apple operating systems, including iOS, macOS, and watchOS. A malicious hardware accessory connected to the device could cause applications to crash or terminate unexpectedly. This could disrupt operations or be used as part of a more complex attack chain.

Technical details

A buffer overflow vulnerability exists across multiple Apple platforms (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS) due to insufficient bounds checking when handling accessory inputs. An attacker with physical access to a device could use a malicious accessory to trigger this overflow. The primary impact is unexpected application termination (denial of service). Apple has addressed this issue by improving bounds checking in the affected components. Patches are available in iOS/iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, and version 26.6 for tvOS, visionOS, and watchOS.

Affected products

  • Apple iOS and iPadOS < 26.5.2
  • Apple macOS Sequoia < 15.7.8
  • Apple macOS Sonoma < 14.8.8
  • Apple macOS Tahoe < 26.5.2
  • Apple tvOS < 26.6
  • Apple visionOS < 26.6
  • Apple watchOS < 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats