CVE-2026-43811: Buffer Overflow
A race condition was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6. An app may be able to modify protected parts of the file system.
Other sources
Accessibility. This issue was addressed through improved state management.
— Apple
Accounts Framework. This issue was addressed with improved data protection.
— Apple
Accounts. An authorization issue was addressed with improved state management.
— Apple
AirDrop. A reachable assertion was addressed with improved input validation.
— Apple
APFS. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.7.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.6 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 18.7.10 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 18.7.10 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 26.6 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 26.6 - Configuration
Ensure the affected authorization/permissions logic is updated so an app cannot modify protected parts of the file system; this corresponds to the release note item about protecting file-system areas with improved validation/state management.
File system permissions / protected areas authorization checks and state management (improved) = Implement improved validation/state management to prevent modification of protected parts of the file system
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-64732
- CVE-2026-65404
- CVE-2026-43667
- CVE-2026-64695
- CVE-2026-43801
- CVE-2026-43776
- CVE-2026-64725
- CVE-2026-65355
- CVE-2026-64747
- CVE-2026-64762
- CVE-2026-64707
- CVE-2026-43811
- CVE-2026-64746
- CVE-2026-64734
- CVE-2026-43797
- CVE-2026-43673
- CVE-2026-43744
- CVE-2026-43803
- CVE-2026-43711
- CVE-2026-43738
- CVE-2026-84489
- CVE-2026-43802
- CVE-2026-3784
- CVE-2026-3783
- CVE-2026-43714
- CVE-2026-64742
- CVE-2026-64740
- CVE-2026-43796
- CVE-2026-64692
- CVE-2026-64716
- CVE-2026-28990
- CVE-2026-43661
- CVE-2026-43818
- CVE-2026-64693
- CVE-2026-64714
- CVE-2026-39877
- CVE-2026-64760
- CVE-2026-64749
- CVE-2026-64744
- CVE-2026-43778
- CVE-2026-64735
- CVE-2026-43822
- CVE-2026-43799
- CVE-2026-64700
- CVE-2026-43724
- CVE-2026-43769
- CVE-2026-43722
- CVE-2026-64721
- CVE-2026-43809
- CVE-2026-43757
- CVE-2026-43754
- CVE-2026-64723
- CVE-2026-39868
- CVE-2026-43810
- CVE-2026-64709
- CVE-2026-64717
- CVE-2026-4424
- CVE-2026-28973
- CVE-2026-64739
- CVE-2026-64743
- CVE-2026-64738
- CVE-2026-64724
- CVE-2026-43723
- CVE-2026-28960
- CVE-2026-43807
- CVE-2026-43733
- CVE-2026-43729
- CVE-2026-64772
- CVE-2026-64774
- CVE-2026-64770
- CVE-2026-64769
- CVE-2026-64722
- CVE-2026-64768
- CVE-2026-64771
- CVE-2026-43812
- CVE-2026-64764
- CVE-2026-64763
- CVE-2026-64766
- CVE-2026-64765
- CVE-2026-43800
- CVE-2026-28996
- CVE-2026-43658
- CVE-2026-65338
- CVE-2026-43795
- CVE-2026-28984
- CVE-2026-28958
- CVE-2026-28947
- CVE-2026-43727
- CVE-2026-43735
- CVE-2026-39872
- CVE-2026-43663
- CVE-2026-65334
- CVE-2026-64757
- CVE-2026-64784
- CVE-2026-43676
- CVE-2026-65331
- CVE-2026-65335
- CVE-2026-65332
- CVE-2026-65333
- CVE-2026-65337
- CVE-2026-65336
- CVE-2026-65340
- CVE-2026-65351
- CVE-2026-64781
- CVE-2026-64782
- CVE-2026-65341
- CVE-2026-64715
- CVE-2026-43734
- CVE-2026-43726
- CVE-2026-43699
- CVE-2026-43742
- CVE-2026-64780
- CVE-2026-43794
- CVE-2026-43725
- CVE-2026-43731
- CVE-2026-43705
- CVE-2026-43708
- CVE-2026-43700
- CVE-2026-43701
- CVE-2026-43745
- CVE-2026-64787
- CVE-2026-43720
- CVE-2026-64778
- CVE-2026-43821
- CVE-2026-64779
- CVE-2026-43717
- CVE-2026-43746
- CVE-2026-28979
- CVE-2026-64719
- CVE-2026-64726
- CVE-2026-64755
- CVE-2026-64733
- CVE-2026-65353
- CVE-2026-28928
- CVE-2026-43748
- CVE-2026-65407
- CVE-2026-43730
- CVE-2026-43813
- CVE-2026-43702
- CVE-2026-43753
- CVE-2026-64705
- CVE-2026-43780
- CVE-2026-64758
- CVE-2026-64754
- CVE-2026-43805
- CVE-2026-43739
- CVE-2026-43816
- CVE-2026-64729
- CVE-2026-43814
- CVE-2026-28931
- CVE-2026-43817
- CVE-2026-64775
- CVE-2026-64720
- CVE-2026-64751
- CVE-2026-65357
- CVE-2026-65371
- CVE-2026-43808
- CVE-2026-64711
- CVE-2026-64741
- CVE-2026-43762
- CVE-2026-28938
- CVE-2026-64713
- CVE-2026-64730
- CVE-2026-64728
- CVE-2026-64783
- CVE-2026-43804
- CVE-2026-64718
Frequently Asked Questions
What is the severity of CVE-2026-43811?
The severity of CVE-2026-43811 is medium with a CVSS score of 4.7.
How do I fix CVE-2026-43811?
To fix CVE-2026-43811, update to iOS 26.6 or iPadOS 26.6.
What does CVE-2026-43811 affect?
CVE-2026-43811 affects the Apple iPadOS and Apple iOS platforms.
What type of vulnerability is CVE-2026-43811?
CVE-2026-43811 involves a race condition that can lead to unauthorized modification of protected parts of the file system.
What improvements were made in CVE-2026-43811 to address the issue?
CVE-2026-43811 was addressed through improved checks and state management.