CVE-2026-43679: Input Validation
802.1X. An authentication issue was addressed with improved state management.
Other sources
Accounts. An authorization issue was addressed with improved state management.
— Apple
Audio. A type confusion issue was addressed with improved memory handling.
— Apple
Audio. A use-after-free issue was addressed with improved memory management.
— Apple
CoreMedia. An out-of-bounds access issue was addressed with improved bounds checking.
— Apple
CoreUtils. A null pointer dereference was addressed with improved input validation.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.4 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 26.4
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-28865
- CVE-2026-28877
- CVE-2026-28879
- CVE-2026-28822
- CVE-2026-20690
- CVE-2026-28886
- CVE-2026-28878
- CVE-2025-14524
- CVE-2026-43679
- CVE-2026-28870
- CVE-2025-64505
- CVE-2026-28868
- CVE-2026-28867
- CVE-2026-20698
- CVE-2026-20687
- CVE-2026-28882
- CVE-2026-28896
- CVE-2026-28863
- CVE-2026-28864
- CVE-2026-28860
- CVE-2026-28856
- CVE-2026-28852
- CVE-2026-20665
- CVE-2026-28859
- CVE-2026-20691
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker needs physical access to a locked Apple Watch.
What information could be exposed?
An attacker may be able to view the user's contacts.
Which update fixes the issue?
Apple states that the issue is fixed in watchOS 26.4.