CVE-2026-43717: Double Free
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Other sources
Accessibility. This issue was addressed through improved state management.
— Apple
Accounts Framework. This issue was addressed with improved data protection.
— Apple
Accounts. An authorization issue was addressed with improved state management.
— Apple
AirDrop. A reachable assertion was addressed with improved input validation.
— Apple
APFS. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.5.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.7.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.6 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 26.5.2 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 18.7.10 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 18.7.10 - Upgrade
Upgrade
iOS (Safari 26.5.2)to a version that resolves this vulnerability.Fixed in 26.5.2 - Upgrade
Upgrade
iPadOS (Safari 26.5.2)to a version that resolves this vulnerability.Fixed in 26.5.2 - Upgrade
Upgrade
macOS Tahoeto a version that resolves this vulnerability.Fixed in 26.5.2 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 26.6 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 26.6 - Compensating control
For the described network information transmission issue, use HTTPS when sending information over the network.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-43704
- CVE-2026-43700
- CVE-2026-43735
- CVE-2026-43734
- CVE-2026-43726
- CVE-2026-43709
- CVE-2026-43699
- CVE-2026-43742
- CVE-2026-43732
- CVE-2026-43731
- CVE-2026-43715
- CVE-2026-43727
- CVE-2026-43725
- CVE-2026-43663
- CVE-2026-39872
- CVE-2026-43712
- CVE-2026-43716
- CVE-2026-43676
- CVE-2026-43740
- CVE-2026-43713
- CVE-2026-43708
- CVE-2026-43707
- CVE-2026-43705
- CVE-2026-43701
- CVE-2026-43745
- CVE-2026-43720
- CVE-2026-43721
- CVE-2026-28979
- CVE-2026-43718
- CVE-2026-43717
- CVE-2026-43746
- CVE-2026-43743
- CVE-2026-43724
- CVE-2026-43722
- CVE-2026-39868
- CVE-2026-43706
- CVE-2026-43703
- CVE-2026-43807
- CVE-2026-64732
- CVE-2026-65404
- CVE-2026-43667
- CVE-2026-64695
- CVE-2026-43801
- CVE-2026-43776
- CVE-2026-64725
- CVE-2026-65355
- CVE-2026-64747
- CVE-2026-64762
- CVE-2026-64707
- CVE-2026-43811
- CVE-2026-64746
- CVE-2026-64734
- CVE-2026-43797
- CVE-2026-43673
- CVE-2026-43744
- CVE-2026-43803
- CVE-2026-43711
- CVE-2026-43738
- CVE-2026-84489
- CVE-2026-43802
- CVE-2026-3784
- CVE-2026-3783
- CVE-2026-43714
- CVE-2026-64742
- CVE-2026-64740
- CVE-2026-43796
- CVE-2026-64692
- CVE-2026-64716
- CVE-2026-28990
- CVE-2026-43661
- CVE-2026-43818
- CVE-2026-64693
- CVE-2026-64714
- CVE-2026-39877
- CVE-2026-64760
- CVE-2026-64749
- CVE-2026-64744
- CVE-2026-43778
- CVE-2026-64735
- CVE-2026-43822
- CVE-2026-43799
- CVE-2026-64700
- CVE-2026-43769
- CVE-2026-64721
- CVE-2026-43809
- CVE-2026-43757
- CVE-2026-43754
- CVE-2026-64723
- CVE-2026-43810
- CVE-2026-64709
- CVE-2026-64717
- CVE-2026-4424
- CVE-2026-28973
- CVE-2026-64739
- CVE-2026-64743
- CVE-2026-64738
- CVE-2026-64724
- CVE-2026-43723
- CVE-2026-28960
- CVE-2026-43733
- CVE-2026-43729
- CVE-2026-64772
- CVE-2026-64774
- CVE-2026-64770
- CVE-2026-64769
- CVE-2026-64722
- CVE-2026-64768
- CVE-2026-64771
- CVE-2026-43812
- CVE-2026-64764
- CVE-2026-64763
- CVE-2026-64766
- CVE-2026-64765
- CVE-2026-43800
- CVE-2026-28996
- CVE-2026-43658
- CVE-2026-65338
- CVE-2026-43795
- CVE-2026-28984
- CVE-2026-28958
- CVE-2026-28947
- CVE-2026-65334
- CVE-2026-64757
- CVE-2026-64784
- CVE-2026-65331
- CVE-2026-65335
- CVE-2026-65332
- CVE-2026-65333
- CVE-2026-65337
- CVE-2026-65336
- CVE-2026-65340
- CVE-2026-65351
- CVE-2026-64781
- CVE-2026-64782
- CVE-2026-65341
- CVE-2026-64715
- CVE-2026-64780
- CVE-2026-43794
- CVE-2026-64787
- CVE-2026-64778
- CVE-2026-43821
- CVE-2026-64779
- CVE-2026-64719
- CVE-2026-64726
- CVE-2026-64755
- CVE-2026-64733
- CVE-2026-28928
- CVE-2026-65407
- CVE-2026-43730
- CVE-2026-43813
- CVE-2026-43759
- CVE-2026-43702
- CVE-2026-43758
- CVE-2026-43780
- CVE-2026-64758
- CVE-2026-64754
- CVE-2026-43805
- CVE-2026-43739
- CVE-2026-43816
- CVE-2026-64729
- CVE-2026-43814
- CVE-2026-28931
- CVE-2026-43817
- CVE-2026-64775
- CVE-2026-64720
- CVE-2026-64751
- CVE-2026-65357
- CVE-2026-65371
- CVE-2026-43808
- CVE-2026-64741
- CVE-2026-64713
- CVE-2026-64730
- CVE-2026-64783
- CVE-2026-64728
- CVE-2026-64718
- CVE-2026-64727
- CVE-2026-43770
Frequently Asked Questions
What is the severity of CVE-2026-43717?
CVE-2026-43717 has a risk score of 60, indicating a moderate level of severity.
How do I fix CVE-2026-43717?
To fix CVE-2026-43717, ensure that your device is updated to the latest version of Apple iOS, iPadOS, or macOS.
What types of vulnerabilities are associated with CVE-2026-43717?
CVE-2026-43717 involves a race condition, double free issues, and vulnerabilities related to input validation.
What software is affected by CVE-2026-43717?
CVE-2026-43717 affects Apple iOS, Apple iPadOS, and Apple macOS Tahoe.
How can I mitigate the impacts of CVE-2026-43717?
Mitigation for CVE-2026-43717 includes applying software updates provided by Apple promptly.