CVE-2026-43721: Double Free
IOGPUFamily. A race condition was addressed with improved state handling.
Other sources
Kernel. The issue was addressed with improved input sanitization.
— Apple
Kernel. This issue was addressed with improved input validation.
— Apple
libxslt. A double free issue was addressed with improved memory management.
— Apple
libxslt. The issue was addressed with improved memory handling.
— Apple
This issue was addressed through improved state management.
Impact: a malicious website may silently hijack clipboard data
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313478
— Red Hat
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.5.2 - Upgrade
Upgrade
Safari / iOS / iPadOS / macOS (WebKit)to a version that resolves this vulnerability.Fixed in 26.5.2Patch WSA-2026-0004 - Compensating control
Consider mitigating the risk of clipboard hijacking by ensuring sensitive clipboard data is not relied upon on systems affected until the WebKit update to Safari/iOS/iPadOS/macOS 26.5.2 is applied.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-43743
- CVE-2026-43724
- CVE-2026-43722
- CVE-2026-39868
- CVE-2026-43706
- CVE-2026-43703
- CVE-2026-43704
- CVE-2026-43700
- CVE-2026-43735
- CVE-2026-43734
- CVE-2026-43726
- CVE-2026-43709
- CVE-2026-43699
- CVE-2026-43742
- CVE-2026-43732
- CVE-2026-43731
- CVE-2026-43715
- CVE-2026-43727
- CVE-2026-43725
- CVE-2026-43663
- CVE-2026-39872
- CVE-2026-43712
- CVE-2026-43716
- CVE-2026-43676
- CVE-2026-43740
- CVE-2026-43713
- CVE-2026-43708
- CVE-2026-43707
- CVE-2026-43705
- CVE-2026-43701
- CVE-2026-43745
- CVE-2026-43720
- CVE-2026-43721
- CVE-2026-28979
- CVE-2026-43718
- CVE-2026-43717
- CVE-2026-43746
- CVE-2026-64733
- CVE-2026-43801
- CVE-2026-28928
- CVE-2026-64725
- CVE-2026-43730
- CVE-2026-64747
- CVE-2026-43813
- CVE-2026-64746
- CVE-2026-64734
- CVE-2026-43673
- CVE-2026-43744
- CVE-2026-43803
- CVE-2026-43711
- CVE-2026-43759
- CVE-2026-3784
- CVE-2026-3783
- CVE-2026-43758
- CVE-2026-43714
- CVE-2026-64742
- CVE-2026-43796
- CVE-2026-64692
- CVE-2026-43780
- CVE-2026-64716
- CVE-2026-64758
- CVE-2026-64754
- CVE-2026-64693
- CVE-2026-43805
- CVE-2026-43778
- CVE-2026-64709
- CVE-2026-64735
- CVE-2026-43739
- CVE-2026-43816
- CVE-2026-43822
- CVE-2026-64729
- CVE-2026-43814
- CVE-2026-64700
- CVE-2026-43799
- CVE-2026-28931
- CVE-2026-43817
- CVE-2026-43769
- CVE-2026-43810
- CVE-2026-64775
- CVE-2026-64720
- CVE-2026-64751
- CVE-2026-64721
- CVE-2026-28973
- CVE-2026-64739
- CVE-2026-64743
- CVE-2026-64724
- CVE-2026-43723
- CVE-2026-43807
- CVE-2026-64741
- CVE-2026-64766
- CVE-2026-64765
- CVE-2026-64764
- CVE-2026-64763
- CVE-2026-43800
- CVE-2026-64713
- CVE-2026-64730
- CVE-2026-43821
- CVE-2026-64783
- CVE-2026-64728
- CVE-2026-64757
- CVE-2026-64718
- CVE-2026-64719
- CVE-2026-64726
- CVE-2026-64707
- CVE-2026-64749
- CVE-2026-4424
- CVE-2026-43729
- CVE-2026-64772
- CVE-2026-64771
- CVE-2026-64774
- CVE-2026-64770
- CVE-2026-64769
- CVE-2026-64768
- CVE-2026-43812
- CVE-2026-43804
- CVE-2026-64740
- CVE-2026-64727
- CVE-2026-43770
Frequently Asked Questions
What is the severity of CVE-2026-43721?
CVE-2026-43721 has a severity rating of high with a CVSS score of 7.5.
What types of vulnerabilities are associated with CVE-2026-43721?
CVE-2026-43721 is associated with double free, use after free, race conditions, and input validation vulnerabilities.
Which software is affected by CVE-2026-43721?
CVE-2026-43721 affects Apple iOS, Apple iPadOS, Apple macOS Tahoe, and Apple Safari.
How do I fix CVE-2026-43721?
To fix CVE-2026-43721, update your affected Apple software to the latest version provided by Apple.
What is the nature of the issues addressed in CVE-2026-43721?
CVE-2026-43721 addresses issues including race condition, improved state handling, input sanitization, and memory management.