Description
The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
In plain language
AI Low urgencyThis is a security fix for iPhone, iPad, and Mac: a bad input handling problem that could let an app crash your device or, more seriously, affect sensitive system memory—so you should update to the fixed iOS/iPadOS/macOS versions if you can.
CVE-2026-43724 is a fixed input-sanitization flaw that could allow an app to trigger unexpected system termination and potentially write kernel memory on iOS/iPadOS/macOS; fixed in iOS 26.5.2 and iPadOS 26.5.2 and macOS Tahoe 26.5.2.
What to do now
- Check whether your iPhone/iPad is updated beyond iOS/iPadOS 26.5.2 and whether your Mac is updated beyond macOS Tahoe 26.5.2.
- If any devices are on older versions, update them to iOS 26.5.2 or iPadOS 26.5.2 (for Apple mobile devices) and macOS Tahoe 26.5.2 (for Macs).
- After updating, confirm normal app/device stability and report any persistent crashes to your IT/vendor support team.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Apple Patches iOS and macOS - SANS Internet Storm Centeren·SANS Internet Storm Center· Patch iOS mobile
- Apple Patches Everything (July 2026) - SANS ISCen·SANS Internet Storm Center· Patch macOS zero-day
- June 2026 Apple Updates - SANS Internet Storm Centeren·SANS Internet Storm Center· Patch iOS web-app
- Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugsen·The Hacker News· Patch iOS ai-ml
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-43724 and every CVE in our database. Create a free account — no credit card required.
Create Free Account