CVE-2026-43814
A software bug called use‑after‑free can crash the operating system. The flaw has been fixed in the latest releases of iOS, iPadOS, macOS, tvOS, and watchOS. Users should update to those versions to avoid crashes.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
iOS 26.5 and earlier, iPadOS 26.5 and earlier, macOS Tahoe 26.5 and earlier, tvOS 26.5 and earlier, watchOS 26.5 and earlier. The typical user is anyone running these Apple operating systems on their devices.
Real-world impact
An attacker could cause the device to crash, potentially disrupting services or enabling denial‑of‑service attacks.
Why this severity
The CVSS score is high because the flaw can be triggered without any special permissions or user interaction and can completely compromise confidentiality, integrity, and availability by crashing the system.
What to do about it
- 011. Update to iOS 26.6 or later.
- 022. Update to iPadOS 26.6 or later.
- 033. Update to macOS Tahoe 26.6 or later.
- 044. Update to tvOS 26.6 or later.
- 055. Update to watchOS 26.6 or later.
NVD-referenced vendor advisory
Timeline
- Jul 27, 2026 · 3d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 28, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- support.apple.com/en-us/128066release notesvendor advisory
- support.apple.com/en-us/128067release notesvendor advisory
- support.apple.com/en-us/128068release notesvendor advisory
- support.apple.com/en-us/128069release notesvendor advisory