CVE-2026-43666
Out-of-Bounds Write in Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS
Publication date: 2026-05-11
Last updated on: 2026-05-11
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | ios | 18.7.9 |
| apple | ipados | 18.7.9 |
| apple | ios | 26.5 |
| apple | ipados | 26.5 |
| apple | macos_sequoia | 15.7.7 |
| apple | macos_sonoma | 14.8.7 |
| apple | macos_tahoe | 26.5 |
| apple | tvos | 26.5 |
| apple | visionos | 26.5 |
| apple | watchos | 26.5 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
An attacker on the local network may be able to exploit this vulnerability to cause a denial-of-service (DoS) condition.
This means that the affected device or system could become unresponsive or crash, disrupting normal operations.
Can you explain this vulnerability to me?
This vulnerability is an out-of-bounds write issue that was addressed by improving bounds checking in affected Apple operating systems.
An out-of-bounds write occurs when a program writes data outside the boundaries of allocated memory, which can lead to unexpected behavior or crashes.
In this case, the issue could be exploited by an attacker on the local network.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, update your Apple devices to the fixed versions of the operating systems as soon as possible.
- Update iOS and iPadOS devices to versions 18.7.9 or 26.5.
- Update macOS Sequoia to 15.7.7, macOS Sonoma to 14.8.7, and macOS Tahoe to 26.5.
- Update tvOS, visionOS, and watchOS devices to version 26.5.
These updates include improved bounds checking that address the out-of-bounds write issue and prevent potential denial-of-service attacks from local network attackers.