CVE-2026-43706
published 2026-06-29CVE-2026-43706: A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.18%
8.0th percentile
A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 26.5.2 | 26.5.2 |
| apple | ipados | < 26.5.2 | 26.5.2 |
| apple | iphone_os | < 26.5.2 | 26.5.2 |
| apple | macos | < 26.5.2 | 26.5.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple iOS/iPadOS/macOS up to 26.5.1 Web double free
vuldb·2026-06-30·CVSS 6.5
CVE-2026-43706 [MEDIUM] Apple iOS/iPadOS/macOS up to 26.5.1 Web double free
A vulnerability classified as problematic has been found in Apple iOS, iPadOS and macOS up to 26.5.1. This affects an unknown function of the component Web Handler. The manipulation leads to double free.
This vulnerability is listed as CVE-2026-43706. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
A double free issue was addressed with improved memory management.
ghsa_unreviewed·2026-06-29
CVE-2026-43706 [MEDIUM] CWE-415 A double free issue was addressed with improved memory management.
A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash.
No detection rules found.
No public exploits indexed.
2026-06-29
Published