Video-Processing Memory Corruption in Apple iOS, iPadOS, macOS, tvOS, watchOS
CVSS
—
EPSS
—
Published
()
Modified
AI analysis
CVE-2026-43702 is a memory-handling flaw in Apple's operating systems that is triggered when a device processes a maliciously crafted video file. Successful exploitation can cause unexpected app termination (denial of service) or corruption of process memory, which in Apple's own disclosure language creates a memory-corruption condition in the media-handling path. The flaw affects iPhones, iPads, Macs (both macOS Sequoia and Tahoe), Apple TV, and Apple Watch, and was addressed with improved memory handling in Apple's September updates. There is no CVSS score yet, no public proof-of-concept, and no indication of in-the-wild exploitation. Users are exposed primarily through playing or previewing video files received from untrusted sources, such as messaging attachments or downloads.
What to do: Patch all Apple devices to the fixed releases: iOS/iPadOS 26.6 or 26.7, macOS Sequoia 15.8 or macOS Tahoe 26.6/26.7, tvOS 26.6, and watchOS 26.6, prioritizing via MDM in managed fleets. Instruct users to avoid opening or previewing video files from untrusted sources. Treat reports of apps crashing or behaving erratically during video playback as a potential indicator and verify OS versions fleet-wide.
Affected
Apple iOS
versions prior to iOS 26.6 (fixed in iOS 26.6; also fixed in iOS 26.7)
Apple iPadOS
versions prior to iPadOS 26.6 (fixed in iPadOS 26.6; also fixed in iPadOS 26.7)
Apple macOS Sequoia
versions prior to macOS Sequoia 15.8 (fixed in 15.8)
Apple macOS Tahoe
versions prior to macOS Tahoe 26.6 (fixed in 26.6; also fixed in 26.7)
Apple tvOS
versions prior to tvOS 26.6 (fixed in 26.6)
Apple watchOS
versions prior to watchOS 26.6 (fixed in 26.6)
Estimated exposure
massplausibly hundreds of millions of devices (Apple's installed base exceeds 1.5 billion active devices, most not yet on the 26.6/26.7/15.8 fix releases at… — Every unpatched iPhone, iPad, Mac, Apple TV, and Apple Watch is affected, and Apple's publicly reported active-device base of over 1.5 billion implies the pre-update install base is in the hundreds of millions.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, iOS 26.7 and iPadOS 26.7, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7, tvOS 26.6, watchOS 26.6. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.
Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.
Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.