DIRAS TAKE
Treat this as a high-priority patch: the flaw is remotely reachable without authentication or user interaction (CVSS vector shows PR:N/UI:N), and vendor updates are available for the affected branches.
What is CVE-2026-43790?
A remote attacker can trigger an out-of-bounds write in the macOS kernel, potentially causing unexpected system termination or corruption of kernel memory; this is tracked as CVE-2026-43790. Affected releases are macOS Golden Gate 27 before 27, macOS Tahoe 26.x before 26.7, and macOS Sequoia 15.x before 15.8. The issue requires network access and does not require authentication or user interaction according to the published CVSS vector, and a kernel memory corruption could lead to more severe impacts. The weakness is classified as CWE-787 (Out-of-bounds Write).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Which versions of Apple macOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 15.x | before 15.8 | 15.8 |
| 26.x | before 26.7 | 26.7 |
| 27.x | before 27 | 27 |
Is CVE-2026-43790 being exploited?
There are no public reports of exploitation of CVE-2026-43790 as of 2026-09-30.
How to fix CVE-2026-43790
- Upgrade macOS to the fixed releases: 15.8, 26.7, or 27 depending on your branch.
- If immediate patching is not possible, restrict network exposure of vulnerable systems and block untrusted inbound traffic.
- Monitor endpoint and kernel logs for crashes or suspicious activity and investigate anomalous kernel memory errors.
- Follow Apple's security advisories for any additional mitigations or image-specific guidance.
Frequently asked questions
Is CVE-2026-43790 being actively exploited?
There are no public reports of active exploitation of CVE-2026-43790 as of 2026-09-30.
Which macOS versions are affected by CVE-2026-43790?
macOS Sequoia 15.x before 15.8, macOS Tahoe 26.x before 26.7, and macOS Golden Gate 27 before 27 are listed as affected.
Is there a patch for CVE-2026-43790?
Yes; Apple published fixes in macOS 15.8, 26.7, and 27 for the affected branches.
Does CVE-2026-43790 require authentication?
No; the published CVSS vector indicates no authentication or user interaction is required (PR:N/UI:N).
References
- nvd.nist.gov/vuln/detail/CVE-2026-43790
- cve.org/CVERecord?id=CVE-2026-43790
- support.apple.com/en-us/149035
- support.apple.com/en-us/149042
- support.apple.com/en-us/149043
- All Apple CVEs on CVE Radar
- CVEs published in September 2026