Junglewise Threat Intelligence

CVE-2026-43816: Apple Multiple Operating Systems Out-of-Bounds Write

CVE-2026-43816 · Severity: info · CVSS 5.5 · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability in Apple's operating systems, including iOS, macOS, and watchOS, could allow a malicious application to cause a sudden system crash or shutdown. This issue affects various Apple devices and could disrupt operations or lead to temporary service unavailability. Users should update their devices to the latest software versions to resolve this issue.

Technical details

An out-of-bounds write vulnerability exists in Apple's iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The flaw is caused by insufficient bounds checking, which can be triggered by a local application. Successful exploitation allows an attacker-controlled app to cause memory corruption leading to unexpected system termination (denial of service). Apple has addressed this issue in versions 26.6 of the respective operating systems by implementing improved bounds checking.

Affected products

  • Apple iOS and iPadOS < 26.6
  • Apple macOS Tahoe < 26.6
  • Apple tvOS < 26.6
  • Apple visionOS < 26.6
  • Apple watchOS < 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats