CVE-2026-43667
published 2026-08-17CVE-2026-43667: A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.33%
26.0th percentile
A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5. An attacker in a privileged network position may be able to cause a denial-of-service.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 18.7.10 | 18.7.10 |
| apple | ios_and_ipados | < 26.5 | 26.5 |
| apple | ipados | < 18.7.10 | 18.7.10 |
| apple | iphone_os | < 18.7.10 | 18.7.10 |
| apple | macos | < 26.5 | 26.5 |
| apple | visionos | < 26.5 | 26.5 |
| apple | watchos | < 26.5 | 26.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A reachable assertion was addressed with improved input validation.
ghsa_unreviewed·2026-08-18
CVE-2026-43667 [MEDIUM] CWE-617 A reachable assertion was addressed with improved input validation.
A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An attacker in a privileged network position may be able to cause a denial-of-service.
VulDB
Apple iOS/iPadOS up to 18.7.9 assertion
vuldb·2026-08-17
CVE-2026-43667 [CRITICAL] Apple iOS/iPadOS up to 18.7.9 assertion
A vulnerability classified as critical was found in Apple iOS and iPadOS. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to reachable assertion.
This vulnerability appears as CVE-2026-43667. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
2026-08-17
Published