LiveActive security incident?Get immediate response
CVE Record

CVE-2026-43757: An out-of-bounds read was addressed with improved bounds checking.

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

CriticalCVSS 9.8Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

A flaw in macOS memory handling may let an app crash the system unexpectedly. Apple addressed it with stronger bounds checking in specified macOS updates. The supplied record rates it critical, although the described impact is limited to system termination and does not establish data theft or code execution.

Executive priority

Prioritize prompt deployment through normal emergency patch governance, especially for broadly used or less-controlled Macs. Avoid claiming confirmed compromise or remote takeover: current evidence establishes a crash risk, while the critical CVSS assessment lacks supporting technical detail in the supplied sources.

Technical view

CVE-2026-43757 is a CWE-125 out-of-bounds read in an unspecified macOS component. Apple reports that an app may cause unexpected system termination. The supplied CVSS 3.1 score is 9.8, but its network attack vector and full confidentiality, integrity, and availability impacts are not explained by the available description.

Likely exposure

Potential exposure exists on Macs not updated to macOS Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6. The supplied affected-version entries are placeholders and do not establish exact vulnerable version ranges, hardware scope, or whether other macOS branches are affected.

Exploitation context

The supplied sources do not report active exploitation, and the CVE is not identified as being in KEV. They state only that an app may trigger unexpected system termination. No prerequisites, affected component, delivery method, or demonstrated confidentiality and integrity impact are provided.

Researcher notes

Public details are sparse: no vulnerable component, parsing surface, trigger format, root cause detail, or precise affected range is supplied. The description indicates bounds-checking remediation and possible denial of service. Treat the CVSS vector cautiously because it appears broader than Apple's stated impact; further vendor detail is needed.

Mitigation direction

  • Update Sequoia systems to macOS 15.7.8 or later.
  • Update Sonoma systems to macOS 14.8.8 or later.
  • Update Tahoe systems to macOS 26.6 or later.
  • Check Apple guidance for unsupported or unlisted macOS branches.
  • Prioritize Macs permitted to install untrusted or externally sourced applications.

Validation and detection

  • Inventory each Mac's macOS branch and exact version.
  • Confirm installed versions meet or exceed Apple's fixed releases.
  • Verify security updates completed successfully after restart.
  • Identify unsupported or unlisted systems requiring vendor clarification.
  • Monitor system-termination reports without attempting exploit reproduction.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-125: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-43757 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
4Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.8CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H3.95.9CISA-ADP

Vulnerability scoring details

Base CVSS 3.1 score

9.8Critical
CVSS 3.1 vector shape for CVE-2026-43757Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
cvssV3_1other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
ApplemacOS0, 0, 0Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-125 · source CWE mapping

Out-of-bounds Read

Out-of-bounds Read represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.