CVE-2026-43793
A flaw in how macOS processes environment variables could let an app crash the system. The issue has been fixed in recent releases of macOS Sequoia, Sonoma, and Tahoe. Users should update to the latest version to avoid the problem.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
macOS users running versions prior to Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6.
Real-world impact
An attacker could cause the operating system to terminate unexpectedly, potentially disrupting services and causing data loss.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited over a network with no authentication or user interaction, and it fully compromises confidentiality, integrity, and availability.
What to do about it
- 01Upgrade macOS to Sequoia 15.7.8 or later.
- 02Upgrade macOS to Sonoma 14.8.8 or later.
- 03Upgrade macOS to Tahoe 26.6 or later.
NVD-referenced vendor advisory
Timeline
- Jul 27, 2026 · 3d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 28, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- support.apple.com/en-us/128067release notesvendor advisory
- support.apple.com/en-us/128071release notesvendor advisory
- support.apple.com/en-us/128072release notesvendor advisory