Improper input validation in macOS - CVE-2026-4424
Published: August 17, 2026
Vulnerability identifier: #VU143738
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-4424
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper input validation in libarchive when parsing input. A remote attacker can supply specially crafted archive data to disclose sensitive information.
Affected software
macOS
visionOS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Apple iOS
iPadOS
Optim
libarchive (Red Hat package)
visionOS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Apple iOS
iPadOS
Optim
libarchive (Red Hat package)
How to mitigate CVE-2026-4424
Install update from vendor's website.
macOS - addressed in versions 26.6 25G72, 14.8.8 23J620, 15.7.8 24G824
Optim - update to 2.0.0
visionOS - update to 26.6
Apple iOS - addressed in versions 18.7.10 22H374, 26.6 23G71
iPadOS - addressed in versions 18.7.10 22H374, 26.6 23G71
libarchive (Red Hat package) - update to 3.7.7-8.el10_1
Optim - update to 2.0.0
visionOS - update to 26.6
Apple iOS - addressed in versions 18.7.10 22H374, 26.6 23G71
iPadOS - addressed in versions 18.7.10 22H374, 26.6 23G71
libarchive (Red Hat package) - update to 3.7.7-8.el10_1
External References
Related Security Bulletins
- Multiple vulnerabilities in macOS Tahoe
- Multiple vulnerabilities in macOS Sequoia
- Multiple vulnerabilities in macOS Sonoma
- Red Hat Enterprise Linux 10 update for libarchive
- Multiple vulnerabilities in iOS 26 and iPadOS 26
- Multiple vulnerabilities in Apple visionOS
- Multiple vulnerabilities in iOS 18 and iPadOS 18
- Multiple vulnerabilities in IBM Optim