CVE-2026-43764
An integer overflow in macOS can cause the system to terminate unexpectedly. Apple fixed the issue with improved input validation in newer releases. Users on older versions should update to avoid the risk.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
macOS Sequoia, Sonoma, and Tahoe users running versions earlier than 15.7.8, 14.8.8, and 26.6 respectively.
Real-world impact
An attacker could trigger a crash that disrupts services and may enable further exploitation if the crash is part of a larger attack chain.
Why this severity
The CVSS score of 9.8 reflects that the flaw can compromise confidentiality, integrity, and availability without requiring authentication or user interaction, making it a critical vulnerability.
What to do about it
- 011. Update macOS to at least Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6.
- 022. Restart the computer to complete the update.
NVD-referenced vendor advisory
Timeline
- Jul 27, 2026 · 3d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 28, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- support.apple.com/en-us/128067release notesvendor advisory
- support.apple.com/en-us/128071release notesvendor advisory
- support.apple.com/en-us/128072release notesvendor advisory