ZeroHour

CVE-2026-43684

mass

Kernel Use-After-Free in Apple iOS, iPadOS, and macOS

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-43684 is a use-after-free vulnerability in Apple's kernel memory management affecting iOS, iPadOS, and macOS. The flaw is triggered by an app running on the device: a malicious or already-compromised app may be able to cause unexpected system termination or corrupt kernel memory. Kernel memory corruption of this class is significant because it can potentially be developed into a privilege-escalation or sandbox-escape primitive, though Apple's advisory describes only termination and corruption as the impact. Users on iOS and iPadOS versions prior to 26.7, macOS Sequoia prior to 15.8, and macOS Golden Gate prior to 27 are affected, with fixes shipped in iOS/iPadOS 26.7, macOS Sequoia 15.8, and macOS Golden Gate 27. No public proof-of-concept is known and there is no indication of in-the-wild exploitation at this time.

What to do: Patch iPhones and iPads to iOS/iPadOS 26.7 and Macs to macOS Sequoia 15.8 or macOS Golden Gate 27, pushing the updates via MDM on managed fleets as a priority. Because exploitation requires a malicious or already-compromised app on the device, audit installed apps and restrict sideloading or non-App Store software on high-value endpoints. Monitor Apple's security advisory for researcher credit and any added exploitation notes, since kernel use-after-free bugs are common building blocks in full exploit chains and should not sit unpatched.

Affected
Apple iOSprior to 26.7 (fixed in 26.7)
Apple iPadOSprior to 26.7 (fixed in 26.7)
Apple macOS Sequoiaprior to 15.8 (fixed in 15.8)
Apple macOS Golden Gateprior to 27 (fixed in 27)
Estimated exposure
massHundreds of millions of unpatched iPhones, iPads, and Macs (order of magnitude: 10^8+ devices) — Apple's installed base exceeds one billion active devices worldwide and the majority of iPhone/iPad/Mac users typically lag the latest point release in the weeks after disclosure, so the pool of vulnerable-but-patchable devices is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27, macOS Sequoia 15.8. An app may be able to cause unexpected system termination or corrupt kernel memory.

Vendors
apple
Products
ipados, iphone os, macos
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.