CVE-2026-43750
A buffer overflow in macOS can let an application run code outside its sandbox or with elevated privileges. The flaw has been fixed in recent macOS releases. Users should update to the latest version to protect themselves.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
macOS Sequoia, Sonoma, and Tahoe versions prior to 15.7.8, 14.8.8, and 26.6 respectively. Typical users are Mac owners who have not yet upgraded.
Real-world impact
An attacker could execute arbitrary code on the victim’s machine, potentially taking full control or bypassing sandbox restrictions.
Why this severity
The CVSS score of 9.8 reflects a critical vulnerability: it is network‑reachable, requires no authentication or user interaction, and can compromise confidentiality, integrity, and availability of the system.
What to do about it
- 01Upgrade macOS to Sequoia 15.7.8 or later.
- 02Upgrade macOS to Sonoma 14.8.8 or later.
- 03Upgrade macOS to Tahoe 26.6 or later.
NVD-referenced vendor advisory
Timeline
- Jul 27, 2026 · 3d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 28, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- support.apple.com/en-us/128067release notesvendor advisory
- support.apple.com/en-us/128071release notesvendor advisory
- support.apple.com/en-us/128072release notesvendor advisory