Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-43753

CVE-2026-43753: Apple iPadOS Information Disclosure Flaw

CVE-2026-43753 is an information disclosure vulnerability in Apple iPadOS caused by an out-of-bounds read flaw. Attackers with physical access can view sensitive data on locked devices. This article covers affected versions and fixes.

Updated:

CVE-2026-43753 Overview

CVE-2026-43753 is an out-of-bounds read vulnerability [CWE-125] affecting Apple iOS, iPadOS, and macOS. An attacker with physical access to a locked device can read memory beyond an intended buffer boundary. Apple addressed the flaw by adding improved bounds checking in the affected component.

Successful exploitation exposes sensitive user information stored on a locked device. The attack requires physical possession of the target hardware, which limits scale but remains relevant for lost, stolen, or seized devices. Apple shipped fixes across iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.

Critical Impact

An attacker with physical access to a locked Apple device may read sensitive user information from memory without unlocking the device.

Affected Products

  • Apple iOS versions prior to 26.6
  • Apple iPadOS versions prior to 26.6
  • Apple macOS Sequoia prior to 15.7.8, macOS Sonoma prior to 14.8.8, and macOS Tahoe prior to 26.6

Discovery Timeline

  • 2026-07-27 - CVE-2026-43753 published to NVD
  • 2026-07-28 - Last updated in NVD database

Technical Details for CVE-2026-43753

Vulnerability Analysis

CVE-2026-43753 is classified as an out-of-bounds read [CWE-125]. The affected code path reads memory outside the bounds of an allocated buffer when processing input that is accessible while the device is locked. The disclosed content is confidentiality-sensitive, but the flaw does not permit modification of data or disruption of service.

Apple's advisories confirm the fix approach: improved bounds checking on the vulnerable read operation. This indicates the original code lacked a length validation or index check before dereferencing memory. Apple has not released component-level detail beyond the advisory text on pages 128066, 128067, 128071, and 128072.

Exploitation requires physical proximity to the device. No public proof-of-concept, exploit code, or in-the-wild activity has been reported at the time of writing. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Root Cause

The root cause is missing or insufficient bounds validation when the vulnerable component reads from a memory buffer. When a request or input crosses the expected length, the code reads adjacent memory and returns its contents to the caller. Apple's remediation adds explicit bounds enforcement before the read.

Attack Vector

The attack vector is physical. An attacker holding a locked iPhone, iPad, or Mac interacts with an interface reachable from the lock screen. That interaction triggers the vulnerable read path, causing the device to return memory contents that were not intended to be accessible in the locked state. No user interaction from the legitimate owner is required.

The vulnerability has no impact on integrity or availability. Its practical value to an adversary is intelligence gathering from lost, stolen, or briefly unattended devices. See the Apple Security Advisory 128066 for vendor guidance.

Detection Methods for CVE-2026-43753

Indicators of Compromise

  • No public indicators of compromise are associated with CVE-2026-43753 at this time.
  • Physical exploitation typically leaves no network telemetry, so device-side signals are the primary evidence source.

Detection Strategies

  • Inventory managed Apple endpoints and compare installed OS versions against the fixed builds (iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6).
  • Use mobile device management (MDM) compliance reporting to flag devices below the patched versions.
  • Track lost or stolen device reports and correlate them with account activity that may indicate data exposure.

Monitoring Recommendations

  • Enable and monitor MDM version compliance dashboards for Apple fleet OS drift.
  • Review sign-in and access logs for accounts tied to devices reported lost or stolen while running vulnerable versions.
  • Audit lock screen widget and accessibility configurations that expose data from the locked state.

How to Mitigate CVE-2026-43753

Immediate Actions Required

  • Update all iPhones to iOS 26.6 and iPads to iPadOS 26.6.
  • Update Macs to macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, or macOS Tahoe 26.6 as applicable.
  • Enforce patch deployment through MDM policies and verify compliance before closing the ticket.
  • Report lost or stolen devices and initiate remote wipe through Find My or MDM.

Patch Information

Apple released fixes in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Refer to Apple Security Advisory 128066, Apple Security Advisory 128067, Apple Security Advisory 128071, and Apple Security Advisory 128072 for the version matrix and package details.

Workarounds

  • Restrict lock screen access to widgets, notifications, Siri, and Control Center on devices that cannot be updated immediately.
  • Enable data protection features such as Stolen Device Protection on iPhone and full-disk encryption (FileVault) on Mac.
  • Enforce short auto-lock timeouts and strong passcodes through MDM configuration profiles until patching is complete.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.