CVE-2026-43716: Buffer Overflow
IOGPUFamily. A race condition was addressed with improved state handling.
Other sources
Kernel. The issue was addressed with improved input sanitization.
— Apple
Kernel. This issue was addressed with improved input validation.
— Apple
libxslt. A double free issue was addressed with improved memory management.
— Apple
libxslt. The issue was addressed with improved memory handling.
— Apple
MobileAccessoryUpdater. A buffer overflow was addressed with improved bounds checking.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.5.2 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 26.5.2 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 26.5.2 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 26.5.2 - Upgrade
Upgrade
macOS Tahoeto a version that resolves this vulnerability.Fixed in 26.5.2 - Upgrade
Upgrade
WebKit (advisory WSA-2026-0004)to a version that resolves this vulnerability.Patch WSA-2026-0004 - Upgrade
Upgrade
WebKit (Bug 313473)to a version that resolves this vulnerability.Patch 313473
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-43704
- CVE-2026-43700
- CVE-2026-43735
- CVE-2026-43734
- CVE-2026-43726
- CVE-2026-43709
- CVE-2026-43699
- CVE-2026-43742
- CVE-2026-43732
- CVE-2026-43731
- CVE-2026-43715
- CVE-2026-43727
- CVE-2026-43725
- CVE-2026-43663
- CVE-2026-39872
- CVE-2026-43712
- CVE-2026-43716
- CVE-2026-43676
- CVE-2026-43740
- CVE-2026-43713
- CVE-2026-43708
- CVE-2026-43707
- CVE-2026-43705
- CVE-2026-43701
- CVE-2026-43745
- CVE-2026-43720
- CVE-2026-43721
- CVE-2026-28979
- CVE-2026-43718
- CVE-2026-43717
- CVE-2026-43746
- CVE-2026-43743
- CVE-2026-43724
- CVE-2026-43722
- CVE-2026-39868
- CVE-2026-43706
- CVE-2026-43703
- CVE-2026-43807
Frequently Asked Questions
What is the severity of CVE-2026-43716?
CVE-2026-43716 has a medium severity rating of 6.5 according to the CVSS 3.1 metrics.
How do I fix CVE-2026-43716?
To mitigate CVE-2026-43716, users should update their devices to the latest Apple iOS, iPadOS, or macOS versions that include the security patches.
What types of vulnerabilities are associated with CVE-2026-43716?
CVE-2026-43716 is associated with vulnerabilities such as double free, use-after-free, input validation issues, race conditions, and buffer overflows.
Which products are affected by CVE-2026-43716?
CVE-2026-43716 affects Apple iPadOS, Apple Safari, Apple iOS, Apple macOS Tahoe, and Apple iPhone OS.
What does CVE-2026-43716 address regarding kernel and libxslt?
CVE-2026-43716 addresses a race condition with improved state handling in the kernel and a double free issue with improved memory management in libxslt.