CVE-2026-43790
Apple · macOS
A memory handling vulnerability in macOS allows remote, unauthenticated attackers to trigger system termination or kernel memory corruption.
Executive summary
A critical memory corruption vulnerability in Apple macOS allows remote unauthenticated attackers to cause system instability or kernel-level memory compromise.
Vulnerability
This vulnerability involves improper memory handling that can be exploited by an unauthenticated remote attacker. By sending specially crafted input, an attacker can trigger a kernel-level memory corruption event or force an unexpected system termination.
Business impact
The potential for kernel memory corruption poses a severe risk to system integrity and availability. Given the CVSS score of 9.1, this flaw is categorized as critical because it allows remote execution without prior authentication, potentially leading to a total loss of system availability or a platform for further unauthorized kernel-level access.
Remediation
Immediate Action: Update all affected macOS systems to version 15.8, 26.7, or 27 as specified by the vendor advisory to apply the necessary memory handling security patches.
Proactive Monitoring: Monitor system logs for kernel panics, unexpected reboots, or unusual memory-related errors that may indicate an exploitation attempt.
Compensating Controls: Ensure that network-level defenses, such as firewalls and intrusion detection systems, are configured to drop malformed or suspicious traffic directed at critical system services.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability, combined with its ability to impact kernel memory, necessitates an immediate patching cycle for all exposed macOS endpoints. Administrators should prioritize the deployment of the provided security updates to ensure system stability and to prevent potential remote exploitation.
More Apple CVEs all →
History
CVE Brief tracked this CVE 4 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.1 (3.1)
- Analyst report written