Apple patches a 9.1-rated Mac flaw that could crash your machine remotely
A newly listed 'critical' bug sounds terrifying until you notice Apple fixed it the same day it appeared - and there's no sign anyone's actually used it.
A freshly catalogued vulnerability, CVE-2026-43790, has landed with a CVSS score of 9.1 — the sort of number that usually means “drop everything and patch.” The good news: Apple already has. The fix shipped on 14 September 2026, the same day the flaw was made public, folded into macOS Golden Gate 27, macOS Sequoia 15.8 and macOS Tahoe 26.7.
What the bug actually does
According to Apple’s own security notes and the NVD entry, the issue comes down to sloppy memory handling somewhere in macOS that could let a remote attacker cause “unexpected system termination” — in plain English, crash your Mac. Apple says the fix involved “improved memory handling,” which is the company’s standard shorthand for tightening up how a piece of software reads or writes data it shouldn’t.
Crucially, the public summaries don’t describe this as a route to running arbitrary code, stealing files, or taking over a machine. It’s a denial-of-service class bug: something that can knock a system over, not necessarily one that hands an attacker the keys. That’s worth flagging, because a 9.1 score is unusually high for a crash-only bug, and neither Apple’s advisories nor the NVD listing spell out exactly what makes it remotely triggerable or why it scored so severely. Until more technical detail surfaces, that gap between “critical number” and “described impact” is the bit to treat with a raised eyebrow rather than panic.
So who is actually at risk
This affects Mac desktops and laptops running macOS — not iPhones, iPads, Apple Watches, or Windows and Android devices. Apple’s Golden Gate 27 advisory lists current Apple silicon Macs going back to 2020, alongside the new MacBook Neo (2026), while the Tahoe 26.7 notes cover Macs already on that release. If you’re on an older, unsupported macOS version, this particular patch won’t reach you at all — Apple only backports security fixes to versions it currently supports.
There is no mention in either advisory or the NVD record of the flaw being exploited in the wild. Apple’s standard practice is to stay silent on vulnerabilities until a fix exists, which it has here, so this reads as a responsibly disclosed and already-closed hole rather than an active threat campaign.
What to do about it
If you use a Mac, this is a straightforward one: check for a macOS update in System Settings and install it. Given the September 2026 release date and Apple’s naming, you should end up on Golden Gate 27, Sequoia 15.8, or Tahoe 26.7 depending on which major version your Mac is running. Each of those releases also bundles a long list of other fixes — Apple’s Tahoe 26.7 notes alone cover more than a dozen separate issues, from sandbox-escape bugs to problems in Accessibility and APFS — so there’s little reason to delay the update regardless of how this one specific CVE is scored.
The takeaway
A 9.1 rating grabs attention, but the substance here is a crash bug that Apple fixed before most people even heard about it, with no evidence of anyone exploiting it. It’s a solid reminder to keep your Mac’s software updated rather than a reason to worry your machine has been compromised. Update when the prompt appears, and move on.