External risk intelligence

Apple iOS iPadOS macOS tvOS visionOS watchOS Kernel Memory Corruption

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-43810

This vulnerability affects client-side operating systems (iOS, iPadOS, macOS, tvOS, visionOS, watchOS). These products are typically used as personal end-user devices and are not designed or deployed as public-facing internet services, gateways, or edge servers.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Apple operating systems that could allow a remote attacker to cause unexpected system termination or corrupt critical memory. The issue has been addressed in recent updates to iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.

  • A remote attacker could crash systems or corrupt memory.
  • Matters if Apple devices are broadly deployed.
  • Confirm relevance and exposure for Apple devices.

Attack Path

How an attacker could exploit the issue

A remote attacker could trigger this vulnerability by sending specially crafted data over the network, potentially leading to unexpected system termination or kernel memory corruption.

  • No authentication or user interaction needed.
  • Triggered by sending malicious network data.
  • Risk of system crash or memory corruption.

Live Threat

Current exploitation, exposure, and threat context

A remote user could trigger an unexpected system termination or corrupt kernel memory. This issue is addressed by improved memory handling in updated operating systems.

  • Kernel memory corruption is at risk.
  • Unexpected system termination may occur.
  • System stability could be impacted.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects client-side operating systems. Owners of these devices and the infrastructure supporting them, such as platform or endpoint management teams, should first confirm where the affected technology exists within their environment. Prioritize identifying business-critical assets and their accountable owners to plan remediation based on risk.

  • Identify device and owner.
  • Verify asset criticality and exposure.
  • Plan remediation and coordinate updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the software affected by CVE-2026-43810?

This vulnerability affects the core operating systems powering Apple hardware, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. These systems provide the foundational environment for running applications and managing hardware resources on iPhones, iPads, Macs, Apple TVs, Apple Vision Pro, and Apple Watches.

How does CVE-2026-43810 corrupt kernel memory?

The vulnerability involves issues with how the system handles memory, specifically falling under classes like CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), CWE-416 (Use After Free), and CWE-787 (Out-of-bounds Write). These flaws mean the system may incorrectly access or manipulate memory areas reserved for the kernel—the most sensitive part of the OS—potentially leading to crashes or unauthorized memory changes.

What triggers this memory corruption?

The vulnerability is triggered when a device receives specially crafted data over a network. It does not require the user to open a file, click a link, or authenticate. Conversely, simply using the device for normal tasks like browsing or messaging does not trigger the bug; it specifically requires the arrival of malformed network data designed to exploit these memory handling weaknesses.

Why does Halo Surface Signal categorize this as unlikely?

Halo Surface Signal assigns a low likelihood because these are client-side operating systems, not server-side infrastructure. While the vulnerability is network-reachable, these devices are typically end-user hardware, not public-facing web servers or gateways. However, they remain relevant if they are connected to networks where malicious data might be present.

How should I respond to this vulnerability?

The primary response is to update your devices to the latest versions, such as iOS 26.6 or the relevant patches for your specific macOS or other Apple platform. Start by identifying all Apple devices in your environment, focusing on those most critical to your daily tasks or business operations, and coordinate with your team to apply the provided software updates to resolve the underlying memory handling issues.

References