CVE-2026-43753: Use After Free
Accessibility. This issue was addressed through improved state management.
Other sources
Accounts Framework. This issue was addressed with improved data protection.
— Apple
Accounts. A parsing issue in the handling of directory paths was addressed with improved path validation.
— Apple
Accounts. An access issue was addressed with additional sandbox restrictions.
— Apple
afpfs. A buffer overflow was addressed with improved bounds checking.
— Apple
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker with physical access to a locked device may be able to view sensitive user information.
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.7.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.8.8
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-64732
- CVE-2026-64733
- CVE-2026-43801
- CVE-2026-28928
- CVE-2026-43776
- CVE-2026-64725
- CVE-2026-43730
- CVE-2026-64747
- CVE-2026-64707
- CVE-2026-43811
- CVE-2026-43813
- CVE-2026-64746
- CVE-2026-64734
- CVE-2026-43797
- CVE-2026-43673
- CVE-2026-43744
- CVE-2026-43803
- CVE-2026-43711
- CVE-2026-3784
- CVE-2026-3783
- CVE-2026-43753
- CVE-2026-43714
- CVE-2026-64742
- CVE-2026-64740
- CVE-2026-43796
- CVE-2026-64692
- CVE-2026-43780
- CVE-2026-43818
- CVE-2026-64716
- CVE-2026-64758
- CVE-2026-64754
- CVE-2026-64693
- CVE-2026-43805
- CVE-2026-64749
- CVE-2026-43778
- CVE-2026-64709
- CVE-2026-64735
- CVE-2026-43739
- CVE-2026-43816
- CVE-2026-43822
- CVE-2026-64729
- CVE-2026-43814
- CVE-2026-64700
- CVE-2026-43799
- CVE-2026-28931
- CVE-2026-43817
- CVE-2026-43769
- CVE-2026-43810
- CVE-2026-64775
- CVE-2026-64720
- CVE-2026-64751
- CVE-2026-64721
- CVE-2026-4424
- CVE-2026-28973
- CVE-2026-64739
- CVE-2026-64743
- CVE-2026-64724
- CVE-2026-43723
- CVE-2026-43733
- CVE-2026-43729
- CVE-2026-64772
- CVE-2026-64771
- CVE-2026-64722
- CVE-2026-64774
- CVE-2026-64770
- CVE-2026-64769
- CVE-2026-64768
- CVE-2026-64711
- CVE-2026-43812
- CVE-2026-64741
- CVE-2026-64766
- CVE-2026-64765
- CVE-2026-64764
- CVE-2026-64763
- CVE-2026-43800
- CVE-2026-43740
- CVE-2026-64713
- CVE-2026-64730
- CVE-2026-64728
- CVE-2026-64783
- CVE-2026-64757
- CVE-2026-43804
- CVE-2026-43821
- CVE-2026-64718
- CVE-2026-64719
- CVE-2026-64726
- CVE-2026-64755
- CVE-2026-43819
- CVE-2026-43749
- CVE-2026-64767
- CVE-2026-23918
- CVE-2026-64695
- CVE-2026-43781
- CVE-2026-64737
- CVE-2026-43748
- CVE-2026-43681
- CVE-2026-43672
- CVE-2026-43763
- CVE-2026-64702
- CVE-2026-64762
- CVE-2026-64698
- CVE-2026-43756
- CVE-2026-43693
- CVE-2026-43775
- CVE-2026-43759
- CVE-2026-43802
- CVE-2026-64710
- CVE-2026-39875
- CVE-2026-43698
- CVE-2026-43758
- CVE-2026-64708
- CVE-2026-64776
- CVE-2026-64694
- CVE-2026-43747
- CVE-2026-28945
- CVE-2026-43793
- CVE-2026-64691
- CVE-2026-43682
- CVE-2026-28981
- CVE-2026-43773
- CVE-2026-43767
- CVE-2026-43764
- CVE-2026-64697
- CVE-2026-43710
- CVE-2026-43782
- CVE-2026-64744
- CVE-2026-28982
- CVE-2026-43809
- CVE-2026-43757
- CVE-2026-64727
- CVE-2026-64723
- CVE-2026-43754
- CVE-2026-43766
- CVE-2026-64738
- CVE-2026-43806
- CVE-2026-28911
- CVE-2026-43771
- CVE-2026-43772
- CVE-2026-28912
- CVE-2026-43765
- CVE-2026-64731
- CVE-2026-43694
- CVE-2026-39874
- CVE-2026-43792
- CVE-2026-43779
- CVE-2026-43777
- CVE-2026-43760
- CVE-2026-43728
- CVE-2026-43755
- CVE-2026-64745
- CVE-2026-39873
- CVE-2026-64696
- CVE-2026-64704
- CVE-2026-43774
- CVE-2026-43770
- CVE-2026-43768
- CVE-2026-64703
- CVE-2026-64699
- CVE-2026-43750
- CVE-2026-28932
- CVE-2026-28849
- CVE-2026-28936
- CVE-2026-43738
- CVE-2026-28926
- CVE-2025-43325
- CVE-2026-43661
- CVE-2026-39877
- CVE-2026-43724
- CVE-2026-43722
- CVE-2026-39868
- CVE-2026-20672
- CVE-2026-28983
- CVE-2026-28900
- CVE-2026-43703
- CVE-2026-43706
- CVE-2026-43653
- CVE-2026-43807
- CVE-2026-28961
- CVE-2026-28896
- CVE-2026-43665
- CVE-2026-28914
Frequently Asked Questions
What is the severity of CVE-2026-43753?
The severity of CVE-2026-43753 is medium, with a score of 4.6 on the CVSS scale.
How do I fix CVE-2026-43753?
To fix CVE-2026-43753, ensure that your Apple macOS, iPadOS, or iOS is updated to the latest version that addresses the issue.
What types of vulnerabilities are associated with CVE-2026-43753?
CVE-2026-43753 is associated with vulnerabilities such as Use After Free, Race Condition, Buffer Overflow, Input Validation, and Integer Overflow.
Which Apple software is affected by CVE-2026-43753?
CVE-2026-43753 affects Apple macOS, Apple iPadOS, Apple iOS, and specific macOS versions like Tahoe, Sequoia, and Sonoma.
What improvements were made to address CVE-2026-43753?
CVE-2026-43753 was addressed through improved state management, data protection, and path validation.