High severity7.8NVD Advisory· Published Jul 27, 2026· Updated Aug 17, 2026
CVE-2026-43776
CVE-2026-43776
Description
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <26.6
- (no CPE)range: 18.7.10, 26.6
- Range: 18.7.10, 26.6
- Range: 15.7.8
- Range: 26.6
Patches
Vulnerability mechanics
References
4- support.apple.com/en-us/128066nvdRelease NotesVendor Advisory
- support.apple.com/en-us/128067nvdRelease NotesVendor Advisory
- support.apple.com/en-us/128071nvdRelease NotesVendor Advisory
- support.apple.com/en-us/148287nvd
News mentions
7- Apple Patches iOS and macOS, (Mon, Aug 17th)SANS Internet Storm Center · Aug 17, 2026
- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS HijacksThe Hacker News · Aug 3, 2026
- Apple Patches Everything (July 2026), (Wed, Jul 29th)SANS Internet Storm Center · Jul 29, 2026
- Update your iPhone, iPad and Mac to fix Apple security holesMalwarebytes Labs · Jul 28, 2026
- Apple Patches 25 macOS Vulnerabilities in Single July 2026 DisclosureVypr Intelligence · Jul 27, 2026
- macOS Tahoe: 25 Security Flaws Patched in Single July 2026 DisclosureVypr Intelligence · Jul 27, 2026
- Apple iOS 26.6: 25 Vulnerabilities Patched, Including Memory Corruption and Sandbox EscapesVypr Intelligence · Jul 27, 2026