AppleCVE-2026-43747
Apple macOS: out-of-bounds read
High7.1CVE-2026-43747 · Published Jul 27, 2026 · updated Jul 28, 2026
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Parsing a maliciously crafted file may lead to an unexpected app termination.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| macOS Product | < 14.8.8 | 14.8.8 |
| < 15.7.8 | 15.7.8 | |
| < 26.6 | 26.6 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-125
More Apple advisories
All Apple| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 27 | Apple iOS and iPadOS: out-of-bounds write | Critical9.8 | 18.7.10+3 more |
| Jul 27 | Apple iOS and iPadOS: out-of-bounds write | Critical9.8 | 18.7.10+3 more |
| Jul 27 | Apple iOS and iPadOS: buffer overflow | Critical9.8 | 18.7.10+2 more |
| Jul 27 | Apple iOS and iPadOS: out-of-bounds write | Critical9.8 | 18.7.10+2 more |
| Jul 27 | Apple iOS and iPadOS: integer overflow | Critical9.8 | 18.7.10+3 more |
| Jul 27 | A memory initialization issue was addressed with improved memory handling | Critical9.8 | 26.6+2 more |