ZeroHour

CVE-2026-43697

mass

Out-of-Bounds Read When Processing Malicious 3D Files in Apple macOS

CVSS
EPSS
Published
()
Modified
AI analysis

CVE-2026-43697 is an out-of-bounds read in Apple macOS that is triggered when the operating system processes a maliciously crafted 3D file, fixed with improved bounds checking. Successful exploitation would most plausibly cause an application crash or expose a limited amount of process memory (information disclosure), since out-of-bounds reads typically do not permit code execution by themselves. All Mac users running macOS Sequoia prior to 15.8, macOS Tahoe prior to 26.7, and macOS Golden Gate prior to 27 are affected. Apple patched the flaw in its September 'Updates Everything' release wave, and the issue carries no CVSS score yet. There is no evidence of in-the-wild exploitation and no public proof of concept at this time.

What to do: Update to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 via System Settings > General > Software Update as soon as possible. Until patched, users should avoid opening 3D files (e.g., models from untrusted email attachments, downloads, or shared links) in any application that previews or imports 3D content. IT teams should verify fleet-wide patch levels for these three fixed macOS versions.

Affected
Apple macOS Sequoiabefore 15.8 (fixed in 15.8)
Apple macOS Tahoebefore 26.7 (fixed in 26.7)
Apple macOS Golden Gatebefore 27 (fixed in 27)
Estimated exposure
mass≈100M+ devices (Apple's active Mac install base, concentrated on recent macOS versions) — Apple's active Mac installed base is commonly estimated in the hundreds of millions, and Sequoia and Tahoe are recent shipping macOS versions, so a large share of Macs were plausibly unpatched at disclosure, shrinking as users adopt the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted 3D file may lead to an out-of-bounds read.

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.