CVE-2026-43818
HIGH
8.8
CVSS 3.1
Description
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Processing a maliciously crafted image may lead to arbitrary code execution.
Metadata
Severity & Metrics
8.8
HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Apple | iOS and iPadOS | — | 0 < 26.6 |
| Apple | macOS | — | 0 < 14.8.8, 0 < 15.7.8, 0 < 26.6 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | Processing a maliciously crafted image may lead to arbitrary code execution |
| CWE-190 | adp | CWE-190 Integer Overflow or Wraparound |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 8.8 | HIGH | 3.1 | adp | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
References (4)