CVE-2026-43743
published 2026-06-29CVE-2026-43743: A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to…
PriorityP417medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.10%
1.1th percentile
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 26.5.2 | 26.5.2 |
| apple | ipados | < 26.5.2 | 26.5.2 |
| apple | iphone_os | < 26.5.2 | 26.5.2 |
| apple | macos | < 26.5.2 | 26.5.2 |
| apple | macos | >= 26.0 < 26.5.2 | 26.5.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple iOS/iPadOS/macOS up to 26.5.1 denial of service
vuldb·2026-06-30·CVSS 4.7
CVE-2026-43743 [MEDIUM] Apple iOS/iPadOS/macOS up to 26.5.1 denial of service
A vulnerability classified as problematic was found in Apple iOS, iPadOS and macOS up to 26.5.1. This issue affects some unknown processing. Executing a manipulation can lead to denial of service.
This vulnerability is tracked as CVE-2026-43743. The attack is restricted to local execution. No exploit exists.
Upgrading the affected component is advised.
GHSA
A race condition was addressed with improved state handling.
ghsa_unreviewed·2026-06-29
CVE-2026-43743 [MEDIUM] CWE-362 A race condition was addressed with improved state handling.
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination.
No detection rules found.
No public exploits indexed.
2026-06-29
Published