CVE-2026-43747
7.1Apple · macOS
An out-of-bounds read vulnerability in Apple macOS allows for application termination or potential information disclosure when processing maliciously crafted files.
Executive summary
A high-severity out-of-bounds read vulnerability in Apple macOS may allow local attackers to crash applications or potentially expose sensitive data.
Vulnerability
This vulnerability involves an out-of-bounds read flaw triggered during the parsing of malformed files. The attack vector requires user interaction and local access, where the application processes a crafted file to cause an unexpected termination.
Business impact
The vulnerability carries a CVSS score of 7.1, reflecting a high-severity risk due to the potential for service disruption and unauthorized information exposure. Successful exploitation could lead to application crashes, causing significant downtime for critical workflows, or the leakage of memory contents if the out-of-bounds read is chained with other primitives.
Remediation
Immediate Action: Update all affected Apple macOS systems to versions 15.7.8, 14.8.8, or 26.6, respectively, to implement the necessary bounds checking.
Proactive Monitoring: Monitor system logs for repeated application crashes or unusual process behaviors that may indicate an attempt to trigger this vulnerability.
Compensating Controls: Deploy endpoint protection solutions capable of scanning incoming files for malicious signatures before they are opened by users.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS severity and the critical nature of core operating system components, it is essential to prioritize these security updates. Organizations should schedule the deployment of the specified macOS patches across all managed endpoints to prevent potential exploitation of this memory safety issue.