CVE-2026-43776

Summary

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

Affected Software

VendorProductVersion RangeStatus
AppleiOS and iPadOS0 < 26.6affected
ApplemacOS0 < 15.7.8affected
ApplemacOS0 < 26.6affected

Weaknesses

  • Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References