CVE-2026-43794
published 2026-08-17CVE-2026-43794: A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and…
PriorityP351high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.35%
27.1th percentile
A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 18.7.10 | 18.7.10 |
| apple | ios_and_ipados | < 26.6.1 | 26.6.1 |
| apple | ipados | < 18.7.10 | 18.7.10 |
| apple | ipados | >= 26.0 < 26.6.1 | 26.6.1 |
| apple | iphone_os | < 18.7.10 | 18.7.10 |
| apple | iphone_os | >= 26.0 < 26.6.1 | 26.6.1 |
| apple | macos | < 26.6.2 | 26.6.2 |
| apple | macos | >= 26.0 < 26.6.2 | 26.6.2 |
| apple | safari | < 26.6.1 | 26.6.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A memory corruption issue was addressed with improved memory handling.
ghsa_unreviewed·2026-08-18
CVE-2026-43794 [HIGH] CWE-119 A memory corruption issue was addressed with improved memory handling.
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.
VulDB
Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 memory corruption (Nessus ID 335968)
vuldb·2026-08-17
CVE-2026-43794 Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 memory corruption (Nessus ID 335968)
A vulnerability, which was classified as very critical, has been found in Apple iOS, iPadOS and macOS. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2026-43794. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
No detection rules found.
No public exploits indexed.
2026-08-17
Published