CVE-2026-43724PoC(apple / ipados)

HIGHCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (6 mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 17 mentions across 6 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 11 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 8 signals
  • General: 2 classified signals
  • Peaked at 6 mentions on most recent observed day (2026-09-12)
  • 17 total mentions across 6 days

Affected systems

Vendors
Products
ipadosiphone_osmacos

Deep dive

Activity timeline17 mentions / 6d
02356Mentions · 2026-06-30: 3Mentions · 2026-07-13: 1Mentions · 2026-07-14: 5Mentions · 2026-07-15: 1Mentions · 2026-07-31: 1Mentions · 2026-09-12: 6PoC Mentioned / Linked · 2026-07-14: 4PoC Mentioned / Linked · 2026-07-15: 1PoC Mentioned / Linked · 2026-09-12: 6Exploit Tool / Code · 2026-07-14: 4Exploit Tool / Code · 2026-07-15: 1Active Exploitation · 2026-06-30: 1Active Exploitation · 2026-07-13: 1Active Exploitation · 2026-07-14: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-14: 2Patch / Workaround · 2026-09-12: 1Technical Details · 2026-06-30: 2Technical Details · 2026-07-14: 4Technical Details · 2026-07-15: 1Technical Details · 2026-09-12: 106-3007-1307-1407-1507-3109-12
Signal classification6 categories
PoC
847.1%
Active Exploitation
317.6%
General
211.8%
Exploit
211.8%
Disclosure
15.9%
False Positive
15.9%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-06-303
Active Exploitation1Disclosure1General1
2026-07-131
Active Exploitation1
2026-07-145
Active Exploitation1Exploit1False Positive1PoC2
2026-07-151
Exploit1
2026-07-311
General1
2026-09-126
PoC6
Full discourse17 posts
  • Duy Tran@khanhduytran0
    General

    People say CVE-2026-43724 is unreachable on iOS because of _POSIX_SPAWN_RESLIDE. Think again. Test done on MIE-enabled device. (Disclaimer: I can’t promise if anything useful may come out of this, need more research; thanks @Little_34306 for porting to iOS) https://t.co/j5XyNZw6ZH

    Post summary

    The tweet challenges reports that CVE-2026-43724 is unreachable on iOS, noting a test on an MIE-enabled device, but it provides no technical details, exploit code, or patch information.

    53213327535.6K
    13.5K followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-43724 PT ID: PT-2026-53719 Vendor: Apple Product: iOS and iPadOS Description: The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination or write kernel memory. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-53719 • https://github.com/impost0r/Rie #dbugs_vuln

    Post summary

    A functional PoC/exploit for CVE-2026-43724 has been released, with a GitHub link. Apple has issued a patch in recent OS versions.

    03024193.6K
    3.4K followersView on X
  • dbugs@ptdbugs
    Active Exploitation

    A PoC/exploit has been discovered for vulnerability CVE-2026-43724 PT ID: PT-2026-53719 Vendor: Apple Product: iOS, iPadOS, macOS Description: Insufficient input sanitization in Apple platforms allows an app to reach sensitive kernel code paths. This improper input validation can lead to memory corruption, enabling a malicious app running locally to cause unexpected system termination or write to kernel memory. Such exploitation may lead to privilege escalation or full device compromise. Real-world incidents indicate that this issue is being chained with WebKit exploits to escalate from browser-based code execution to full system control. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-53719 • https://github.com/impost0r/Rie #dbugs_vuln

    Post summary

    A PoC/exploit for CVE-2026-43724 has been published showing memory corruption and privilege escalation, with real‑world reports confirming active exploitation, especially when chained with WebKit vulnerabilities.

    0402474.0K
    3.4K followersView on X
  • impostor@impost0r_
    False Positive

    This CVE Does Not Exist Yet: CVE-2026-43724 - Rie https://ret2p.lt/2026/07/13/rie.html gr33tz 2 elites fuckings to l4m3rz or something like that Updated the blogpost with some technical writeup that was partially generated and then read over by me. I'm burnt out from all of this.

    Post summary

    The author claims that CVE-2026-43724 has not yet been identified, providing no PoC, exploit, or patch details, and effectively debunking the vulnerability as a false positive.

    2212191.9K
    2.5K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-43724 PT ID: PT-2026-53719 Vendor: Apple Product: iOS, iPadOS, macOS Description: The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination or write kernel memory. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-53719 • https://github.com/impost0r/Rie #dbugs_vuln

    Post summary

    A proof‑of‑concept/exploit for CVE‑2026‑43724 has been released, with source code hosted on GitHub, and Apple has issued a patch to fix the issue.

    0101031.7K
    3.4K followersView on X
  • impostor 📦‼️| 👑💌 | 🎀🍑@_impost3r_
    Active Exploitation

    I did tell you, I'd do it again, didn't I? For you. 💗 #kirienuki CVE-2026-43724 Also, go fuck yourself Apple, this one was (semi-)weaponized and everything. https://t.co/8ScXmpojPs

    Post summary

    The tweet references CVE-2026-43724, claiming it was 'semi‑weaponized and everything,' which suggests active exploitation, but provides no details on patches, PoC, or technical specifics.

    00130182
    312 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers are chaining WebKit and kernel exploits in Apple devices to escalate from browser-based code execution to full system control. TRC analysis shows the attack path: malicious website → arbitrary code execution (CVE-2026-43724) → privilege escalation → lateral movement across networks. Runtime segmentation helps limit blast radius when endpoints become pivot points. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/june-2026-apple-updates-cve-2026-39868

    Post summary

    The post describes attackers chaining WebKit and kernel exploits (CVE-2026-43724) on Apple devices to achieve privilege escalation and lateral movement, indicating active exploitation in the wild.

    01020159
    2.0K followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-43724: A PoC/exploit has been discovered for vulnerability CVE-2026-43724 PT ID: PT-2026-53719 Vendor: Apple Product: iOS, iPadOS, macOS Description: Insufficient input sanitization in Apple platforms allows an app to reach sensitive kernel code paths. This…

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑43724 has been discovered, revealing that inadequate input sanitization on Apple iOS, iPadOS, and macOS can allow kernel code execution, but no patch or active exploitation is reported.

    10000161
    325 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Source: X search for PoC exploit 2026 Posted: 2026-07-14T14:40:13.000Z Likes: 19 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-43724

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑43724 has been discovered, indicating the vulnerability is publicly acknowledged.

    1000077
    325 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Vendor v26.5.2. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-43724

    Post summary

    A PoC/exploit for CVE-2026-43724 has been discovered, but no further details or mitigation information are provided.

    1000057
    325 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-43724. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-43724

    Post summary

    A proof of concept/exploit has been discovered for CVE-2026-43724, but no further exploit details, patch information, or active exploitation evidence are provided.

    1000076
    325 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Source: X search for PoC exploit 2026 Posted: 2026-07-14T11:36:05.000Z Likes: 20 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-43724

    Post summary

    A proof‑of‑concept/exploit for CVE‑2026‑43724 has been reported, but no further technical details or tool information are supplied.

    1000077
    325 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-43724: A PoC/exploit has been discovered for vulnerability CVE-2026-43724 PT ID: PT-2026-53719 Vendor: Apple Product: iOS and iPadOS Description: The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS…

    Post summary

    A proof‑of‑concept/exploit for CVE‑2026‑43724 has been discovered, and Apple has released a fix in iOS 26.5.2 / iPadOS 26.5.2, but no active exploitation or detailed technical info is provided.

    10000164
    325 followersView on X
  • dbugs@ptdbugs
    Exploit

    CVE-2026-43724: improper input validation in XNU PT ID: PT-2026-53719 (https://dbugs.ptsecurity.com/vulnerability/PT-2026-53719) The researcher discovered a vulnerability CVE-2026-43724 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-43724) in the XNU kernel ("vm_shared_region_slide_page_v5"), which allows kernel memory read and write when handling a slide-info structure version 5. The flaw stems from a missing bounds check on values in the "page_starts[]" array of type "uint16_t", except for the value "0xFFFF". As a result, those values are treated as page offsets, even when they point beyond the page boundary. The vulnerability can be triggered via the system call "__shared_region_map_and_slide_2_np" during dyld shared cache mapping. The exploit implementation "rie.c" proceeds in stages: first, it spawns a child process with the "_POSIX_SPAWN_RESLIDE" flag to create an empty "vm_shared_region", then execution is hijacked via "thread_set_state" with forged signatures using "ptrauth_sign_unauthenticated". On macOS 26.5 (Apple Silicon, vmapple), attempts to exceed allocated pages trigger protection mechanisms but cannot reach the heap, limiting the exploitability. Article: https://ret2p.lt/2026/07/13/rie.html #dbugs_attacks

    Post summary

    The post discloses CVE-2026-43724 in XNU, offers technical details and an exploit implementation, but does not claim active exploitation or provide patches.

    00010390
    2.5K followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 CVE-2026-43724: A PoC has been released for an Apple vulnerability affecting iOS, iPadOS, and macOS that could lead to kernel memory corruption, privilege escalation, or full device compromise. 🔗 https://github.com/impost0r/Rie #CyberSecurity #CVE #Apple #iOS #macOS #ThreatWire

    Post summary

    A PoC has been released for CVE-2026-43724, with a GitHub repository linked; the vulnerability can lead to kernel memory corruption and privilege escalation, but no patch or active exploitation is reported.

    0001082
    87 followersView on X
  • VulDB 🛡@vuldb
    General

    Our CTI team identified a lot of activities targeting Apple iOS and other products (CVE-2026-43724) https://vuldb.com/vuln/374760/cti

    Post summary

    The CTI team notes increased activity targeting Apple iOS linked to CVE‑2026‑43724, but the post lacks specific technical, exploitation, or patch details.

    00010128
    2.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Apple kernel memory corruption via insufficient input sanitization (CVE-2026-43724) CVE-2026-43724 is a kernel-level vulnerability in Apple platforms (iOS/iPadOS/macOS) where inadequate sanitization of inputs from apps can reach sensitive kernel code paths. The underlying flaw is improper input validation leading to memory corruption conditions, including the possibility of unintended writes to kernel memory. An attacker can exploit this by running a malicious app locally on a vulnerable device to feed crafted inputs that trigger the faulty handling, without needing elevated privileges beyond app execution. Successful exploitation can cause unexpected system termination (DoS) and, in worst case, kernel memory modification that may enable privilege escalation or broader device compromise. 👉 Affected: iOS/iPadOS/macOS prior to 26.5.2 | Upgrade to iOS 26.5.2 / iPadOS 26.5.2 / macOS Tahoe 26.5.2

    Post summary

    Apple’s CVE‑2026‑43724 is a kernel‑level memory corruption that can lead to DoS or privilege escalation via malicious locally‑executed apps; the issue is mitigated by upgrading to version 26.5.2.

    00000185
    232 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---

Explore more