ZeroHour

CVE-2026-43683

mass

Out-of-Bounds Read in Apple macOS Could Leak Process Memory

CVSS
EPSS
Published
()
Modified
AI analysis

CVE-2026-43683 is an out-of-bounds read in Apple's macOS that was fixed with improved bounds checking. A malicious or compromised app running on an affected Mac can trigger the flaw to cause unexpected process termination (a crash) or to disclose process memory, potentially exposing sensitive data held in that process such as tokens or other secrets. The flaw affects macOS Sequoia prior to 15.8, macOS Tahoe prior to 26.7, and macOS Golden Gate prior to 27, with fixes shipping in Apple's broad September 14 'Updates Everything' release wave. No CVSS score has been assigned yet, no public proof of concept exists, and there is no evidence of exploitation in the wild.

What to do: Update to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) via System Settings > General > Software Update. Since exploitation requires a malicious app on the Mac, enforce Gatekeeper/notarization policies and restrict software installs to trusted sources. On managed fleets, audit recently added third-party apps and confirm patch compliance against Apple's September security advisory.

Affected
Apple macOS Sequoiaprior to 15.8
Apple macOS Tahoeprior to 26.7
Apple macOS Golden Gateprior to 27
Estimated exposure
mass≈100M+ devices (active Macs running unpatched Sequoia/Tahoe/Golden Gate) — Apple's installed base is estimated at well over 100 million active Macs and the affected versions are the current-generation macOS releases most of those machines run, though the patched fraction will climb quickly after the September…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected process termination or disclose process memory.

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.