Junglewise Threat Intelligence

CVE-2026-43808: Apple iOS use-after-free in Apple Neural Engine

CVE-2026-43808 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS, Apple Iphone Os, Apple watchOS, Apple iPadOS. Vendors: Apple.

Executive brief

Apple's Neural Engine, used for on-device machine learning and AI tasks in iOS and iPadOS, contains a use-after-free memory vulnerability. A malicious app can exploit this to crash the system or potentially execute code, causing unexpected device restarts and degraded system stability.

Technical details

A use-after-free vulnerability in Apple's Neural Engine memory management allows an attacker to reference memory that has been freed. The vulnerability is triggered by a malicious app running on iOS or iPadOS (iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later). The attack requires local execution context and no user interaction beyond app installation. An attacker can cause unexpected system termination (denial of service). The vulnerability is fixed in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, and watchOS 26.6 via improved memory management.

Affected products

  • Apple iOS prior to 26.6
  • Apple iPadOS prior to 26.6
  • Apple macOS Tahoe prior to 26.6
  • Apple tvOS prior to 26.6
  • Apple watchOS prior to 26.6

Timeline

  • 2026-09-14: disclosed
  • 2026-07-27: patched: Security updates released for iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6

References

Related threats