← back

CVE-2026-43692

HIGH · 8.8 EPSS 0.5%
hype MOSTLY HYPE · 28 hack

Vendor patched but no KEV, PoC, or in-wild signal; chatter is automated feed noise.

What: Input validation flaw in macOS (Golden Gate 27, Sequoia 15.8, Tahoe 26.7) allowing remote code execution or app crash; CVSS 8.8 HIGH.

Why it matters: Apple released patches on 2026-09-14, indicating vendor acknowledgment of severity. No KEV listing, no public PoC confirmed in social chatter. Two posts cite the NVD description verbatim without exploitation details or defender triage reports.

Where it's seen: Automated CVE feed posts on Bluesky; no analyst commentary, researcher PoC, or defender questions visible. Posts appear to be syndicated NVD republication rather than organic security discussion.

RISK: HIGH — macOS RCE with CVSS 8.8; Apple patched urgently; affects multiple OS versions.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/16/2026, 3:43:09 AM

Description

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote user may cause an unexpected app termination or arbitrary code execution.

CVSS 3.1 breakdown

Exploitability 2.8 · Impact 5.9
vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected versions

  • apple/macos
    • 15.0 – < 15.8
    • 26.0 – < 26.7

Weaknesses

Vendors

  • apple

Products

  • macos