CVE-2026-43655Patch(apple / ipados)

HIGHCVSS 7.3 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination or read kernel memory.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-06-21); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvoswatchos

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-21: 1Mentions · 2026-06-22: 1PoC Mentioned / Linked · 2026-06-21: 1Active Exploitation · 2026-06-22: 1Patch / Workaround · 2026-06-21: 1Patch / Workaround · 2026-06-22: 1Technical Details · 2026-06-21: 1Technical Details · 2026-06-22: 106-2106-22
Signal classification2 categories
Patch
150.0%
Active Exploitation
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-211
Patch1
2026-06-221
Active Exploitation1
Full discourse2 posts
  • Somair Ansar@SomairAnsar
    Patch

    CVE-2026-43655 UAF Patched in IOS 26.5 https://github.com/Somisomair/CVE-2026-43655-AppleM2ScalerCSCDriver-UAF

    Post summary

    CVE-2026-43655, a use‑after‑free flaw, has been patched in iOS 26.5 and a GitHub repository provides PoC code, with no indication of active exploitation or detailed exploit methods.

    01010212
    17 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    ⚠️ HIGH — CVE-2026-43655 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, mac… EPSS 0.00 (19th pctl) ⚡ Exploit in the wild Full analysis → https://sec.kaitan.id/cves/CVE-2026-43655 #Apple #CyberSecurity #InfoSec

    Post summary

    CVE-2026-43655 is a high‑severity out‑of‑bounds read vulnerability that is actively exploited in the wild, with a patch available in iOS 26.5 and iPadOS 26.5.

    00000197
    82 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplewatchos---

Explore more