CVE-2026-43655
Description
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination or read kernel memory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An out-of-bounds read vulnerability in Apple software could allow a malicious app to cause unexpected system termination or read kernel memory, impacting multiple platforms.
An out-of-bounds read vulnerability in Apple's kernel has been addressed with improved bounds checking in the latest operating system updates. The flaw exists in iOS and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, and watchOS 26.5. [1][2][3][4] The root cause is a missing bounds check that enables an out-of-bounds read, potentially allowing an attacker to access memory beyond the intended buffer.
Exploitation requires only that a malicious app be installed on an affected device; no additional privileges or network access are needed. The vulnerability can be triggered by the app's normal operation, making it a viable attack vector for arbitrary third-party applications. [1][2][3][4]
The impact is twofold: an app may cause unexpected system termination (denial of service) or read kernel memory. Reading kernel memory could lead to the disclosure of sensitive information, such as cryptographic keys or other data contained in the kernel address space. [1][2][3][4]
Apple has released patches for all affected operating systems: iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, and watchOS 26.5. Users are strongly advised to update their devices. The issue was discovered by Seiji Sakurai (@HeapSmasher), who is credited in the security advisories. [1][3][4]
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: <26.5
- Range: <26.5
- Range: <26.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- support.apple.com/en-us/127110nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127115nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127118nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127119nvdRelease NotesVendor Advisory
News mentions
40- Microsoft May 2026 Patch Tuesday fixes 120 flaws, no zero-daysBleepingComputer · May 12, 2026
- End‑to‑End Encrypted RCS Messaging Arrives Across iPhone and AndroidInfosecurity Magazine · May 12, 2026
- Apple Patches Dozens of Vulnerabilities in macOS, iOSSecurityWeek · May 12, 2026
- iOS 26.5 Brings Default End-to-End Encrypted RCS Messaging Between iPhone and AndroidThe Hacker News · May 12, 2026
- Apple Patches Everything, (Mon, May 11th)SANS Internet Storm Center · May 11, 2026
- iPadOS 17.7.11 (21H461)Apple Security Releases · May 11, 2026
- iPadOS 18.7.9 (22H355)Apple Security Releases · May 11, 2026
- iPadOS 15.8.8 (19H422)Apple Security Releases · May 11, 2026
- iPadOS 26.5 (23F77)Apple Security Releases · May 11, 2026
- iPadOS 16.7.16 (20H392)Apple Security Releases · May 11, 2026
- iOS 26.5 RC 2 (23F77)Apple Security Releases · May 8, 2026
- iPadOS 26.5 RC 2 (23F77)Apple Security Releases · May 8, 2026
- Xcode 26.5 RC (17F42)Apple Security Releases · May 4, 2026
- iPadOS 18.7.9 (22H355)Apple Security Releases · May 4, 2026
- iOS 18.7.9 (22H355)Apple Security Releases · May 4, 2026
- visionOS 26.5 RC (23O471)Apple Security Releases · May 4, 2026
- iOS 26.5 RC (23F75)Apple Security Releases · May 4, 2026
- tvOS 26.5 RC (23L471)Apple Security Releases · May 4, 2026
- iPadOS 26.5 RC (23F75)Apple Security Releases · May 4, 2026
- macOS 26.5 RC (25F71)Apple Security Releases · May 4, 2026
- watchOS 26.5 RC (23T570)Apple Security Releases · May 4, 2026
- 27th April – Threat Intelligence ReportCheck Point Research · Apr 27, 2026
- iOS 26.5 beta 4 (23F5069b)Apple Security Releases · Apr 27, 2026
- tvOS 26.5 beta 4 (23L5469a)Apple Security Releases · Apr 27, 2026
- macOS 26.5 beta 4 (25F5068a)Apple Security Releases · Apr 27, 2026
- Xcode 26.5 beta 3 (17F5032f)Apple Security Releases · Apr 27, 2026
- iPadOS 26.5 beta 4 (23F5069b)Apple Security Releases · Apr 27, 2026
- watchOS 26.5 beta 4 (23T5568a)Apple Security Releases · Apr 27, 2026
- visionOS 26.5 beta 4 (23O5468a)Apple Security Releases · Apr 27, 2026
- Apple Fixes iOS Notification Bug Exposing Deleted MessagesInfosecurity Magazine · Apr 23, 2026
- Apple fixes iOS bug that kept deleted notifications, including chat previewsMalwarebytes Labs · Apr 23, 2026
- iOS 18.7.8 (22H352)Apple Security Releases · Apr 22, 2026
- iPadOS 18.7.8 (22H352)Apple Security Releases · Apr 22, 2026
- iPadOS 26.4.2 (23E261)Apple Security Releases · Apr 22, 2026
- App Store Connect UpdateApple Security Releases · Apr 16, 2026
- Apple Expands iOS 18 Security Updates Amid DarkSword ThreatInfosecurity Magazine · Apr 2, 2026
- iPadOS 16.7.15 (20H380)Apple Security Releases · Mar 11, 2026
- iPadOS 15.8.7 (19H411)Apple Security Releases · Mar 11, 2026
- App Store Connect API 4.3Apple Security Releases · Mar 10, 2026
- Siemens SIMATICCISA Alerts