ZeroHour

CVE-2026-43692

mass

Input Validation RCE Flaw in Apple macOS (Sequoia, Tahoe, Golden Gate)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-43692 is an input validation and sanitization weakness in Apple's macOS that allows a remote attacker to cause unexpected application termination or execute arbitrary code on an affected Mac. The exact component and attack vector were not specified in the advisory, but flaws of this class are typically triggered by tricking a target into processing maliciously crafted content or input, and exploitation would let an attacker crash apps or run code in the context of the vulnerable process. All Macs running macOS Sequoia before 15.8, macOS Tahoe before 26.7, or macOS Golden Gate before 27 are affected; Apple patched the issue in those releases, which shipped alongside the company's broad September security updates. The vulnerability has no CVSS score yet, no public proof-of-concept is known, and it is not listed in CISA's Known Exploited Vulnerabilities catalog, indicating no observed in-the-wild exploitation at this time.

What to do: Update affected Macs immediately to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) via System Settings > Software Update, and prioritize the update in MDM/patch management since arbitrary code execution flaws in macOS are prime targets once details emerge. There is no published workaround, so patching is the primary mitigation. After patching, monitor Apple's security advisory and threat intel feeds for the affected component and any emerging exploitation before this CVE receives a CVSS score.

Affected
Apple macOS Sequoiabefore 15.8 (fixed in 15.8)
Apple macOS Tahoebefore 26.7 (fixed in 26.7)
Apple macOS Golden Gatebefore 27 (fixed in 27)
Estimated exposure
massPotentially hundreds of millions of Macs; Apple's active Mac installed base is commonly estimated at well over 100 million devices, most running the affected… — Estimated from Apple's publicly cited active device/Mac installed base and typical macOS adoption rates on currently supported hardware, since this flaw affects the three most recent macOS generations.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote user may cause an unexpected app termination or arbitrary code execution.

Vendors
apple
Products
macos
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple's coordinated rollout patches 273 unique vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS and Safari, including remote code execution flaws.

Apple shipped one of its largest coordinated security updates on September 14, 2026, fixing 273 unique CVEs across iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27 and Xcode 27. Highlights include CVE-2026-65414, a Bluetooth out-of-bounds write enabling remote code execution, and CVE-2026-84607, an AVEVideoEncoder race condition granting kernel privileges to sandboxed apps. macOS Golden Gate 27 covers the broadest set with 210 CVEs, and Apple states none of the flaws were exploited in the wild.

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

Apple's record patch cycle fixes 260+ CVEs across iOS 27 and macOS 27, including CUPS remote code execution, with no active exploitation reported.

Apple patched more than 260 CVEs across its operating systems and software, its largest single patch cycle ever, with iOS 27 fixing 122 flaws and macOS 27 Golden Gate fixing 204. Notable bugs include CVE-2026-43692, a CUPS validation issue allowing remote code execution, and CVE-2026-43689, an iOS privilege-escalation flaw granting root access. Ten CVEs were credited to AI-assisted bug hunting, including CVE-2026-65410 and CVE-2026-65409 found by Calif with Claude and Anthropic Research. None of the vulnerabilities are listed as actively exploited.