ZeroHour

CVE-2026-43686

mass

Kernel Use-After-Free in Apple NFS Client Across iOS, macOS, and watchOS

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-43686 is a use-after-free vulnerability in Apple's kernel NFS client, disclosed in Apple's September 2026 mass update. It is triggered when a device connects to (mounts a share from) a malicious NFS server, which can lead to kernel memory corruption — typically enough to crash the device or potentially execute code with kernel privileges. All unpatched iPhones, iPads, Macs, Apple TVs, Vision Pro headsets, and Apple Watches are affected, though practical exploitation requires the target to actually connect to an attacker-controlled NFS server, which is uncommon for consumers and mostly plausible in enterprise/managed-network or automount scenarios. No CVSS score has been assigned, no public proof-of-concept is known, and the flaw is not in the CISA KEV catalog, with no reports of in-the-wild exploitation. The issue was fixed with improved memory management in the September 2026 OS releases.

What to do: Patch to the fixed releases: iOS/iPadOS 26.7 or 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. Users and admins should avoid mounting NFS shares from untrusted networks or unknown servers, and enterprise teams should audit automount/NFS configuration profiles so managed devices only connect to vetted NFS infrastructure. Watch for a CVSS score and any follow-on advisory, since kernel memory corruption flaws in Apple platforms are frequently combined with other bugs in chained attacks.

Affected
Apple iOSfixed in iOS 26.7 and iOS 27; earlier versions affected
Apple iPadOSfixed in iPadOS 26.7 and iPadOS 27; earlier versions affected
Apple macOS Sequoiafixed in macOS Sequoia 15.8; earlier versions affected
Apple macOS Tahoefixed in macOS Tahoe 26.7; earlier versions affected
Apple macOS Golden Gatefixed in macOS Golden Gate 27; earlier versions affected
Apple tvOSfixed in tvOS 27; earlier versions affected
Apple visionOSfixed in visionOS 27; earlier versions affected
Apple watchOSfixed in watchOS 27; earlier versions affected
Estimated exposure
mass≈1–2 billion active Apple devices potentially affected, but the practically exploitable subset (devices mounting NFS shares) is far smaller — likely enterprise… — Apple publicly cites roughly 2 billion active devices across iOS, iPadOS, macOS, watchOS, tvOS, and visionOS, but the attack requires a victim to connect to a malicious NFS server, a configuration most consumers never use, so realistic…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may lead to kernel memory corruption.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.