6.5mediumMedium

CVE-2026-43687

Apple Ipados

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may disclose kernel memory.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is reachable over a network, without needing local access.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, no account is needed.
  • Beyond that, someone has to be persuaded to take an action first.

Scoring

CVSS
6.5 (v3.1)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness
CWE-200
Assigned by
product-security@apple.com

Dates

Published
2026-09-14
Last modified
2026-09-15
Sources
NVD

Affected products

  • Apple Ipados- 26.7
  • Apple Iphone Os- 26.7
  • Apple Macos26.0 - 26.7
  • Apple Tvos- 27.0
  • Apple Visionos- 27.0
  • Apple Watchos- 27.0

As listed in the NVD configuration data. Not a statement about your estate.

References