Improper input validation in macOS - CVE-2026-43718
Published: July 8, 2026
Vulnerability identifier: #VU137114
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-43718
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in WebRTC. A remote attacker can trick the victim into opening a specially crafted file and perform an unexpected Safari crash.
Affected software
macOS
visionOS
tvOS
Apple iOS
iPadOS
watchOS
Apple Safari
visionOS
tvOS
Apple iOS
iPadOS
watchOS
Apple Safari
How to mitigate CVE-2026-43718
Install update from vendor's website.
macOS - update to 26.5.2 25F84
visionOS - update to 26.6
tvOS - update to 26.6 23L773
Apple Safari - update to 26.5.2
Apple iOS - update to 26.5.2 23F84
iPadOS - update to 26.5.2 23F84
watchOS - update to 26.6 23U67
visionOS - update to 26.6
tvOS - update to 26.6 23L773
Apple Safari - update to 26.5.2
Apple iOS - update to 26.5.2 23F84
iPadOS - update to 26.5.2 23F84
watchOS - update to 26.6 23U67