Junglewise Threat Intelligence

CVE-2026-43823: Apple swift-crypto double-free in RSA public key initialization

CVE-2026-43823 · Severity: info · CVSS 9.8 · Published 2026-07-23

Vendors: Apple.

Executive brief

Apple's Swift Crypto library, which provides cryptographic functions for Swift applications, contains a memory management flaw. When an application attempts to process a malformed or invalid RSA public key, the library may crash or allow for unpredictable behavior due to a memory error. This could potentially be used by an attacker to disrupt services or gain unauthorized control over an application that processes public keys from untrusted sources.

Technical details

A double-free vulnerability exists in Apple's swift-crypto library when initializing RSA public keys. The flaw occurs when BoringSSL fails to decode a public key from provided DER or PEM bytes; the underlying EVP_PKEY* object is freed once in a catch block and subsequently freed again during deinitialization. This affects _RSA.Encryption.PublicKey, _RSA.Signing.PublicKey, and _RSA.BlindSigning.PublicKey. An attacker providing malformed key data to an application using these APIs can trigger a heap corruption, leading to a denial-of-service (crash) or potentially arbitrary code execution. The issue is resolved in version 4.5.1.

Affected products

  • Apple swift-crypto >= 3.2.0, <= 4.5.0

Timeline

  • 2026-07-16: advisory: GitHub Security Advisory published
  • 2026-07-23: disclosed: NVD publication date
  • 2026-07-23: patched: Vulnerability addressed in version 4.5.1

References

Related threats