CVE-2026-43738

Summary

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted asset catalog may result in disclosure of process memory.

Affected Software

VendorProductVersion RangeStatus
AppleiOS and iPadOS0 < 18.7.10affected
ApplemacOS0 < 14.8.8affected
ApplemacOS0 < 15.7.8affected

Weaknesses

  • Processing a maliciously crafted asset catalog may result in disclosure of process memory

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References