Apple patched the Neural Engine. CVE-2026-43748 is an Apple Neural Engine driver vulnerability — CVSS 9.8 — described publicly as an out-of-bounds write reachable from a sandboxed app. Fixed builds include macOS Sequoia 15.7.8, macOS Tahoe 26.6, and matching iOS updates on the vendor track SecurityOnline summarised on 3 September 2026.
SecurityOnline’s 3 September 2026 reporting said there was no confirmed in-the-wild exploitation for this issue on the materials they cited. Researchers published a proof of concept; this piece will not describe it, will not walk heap steps, and will not explain how to trigger the bug. The story is patch now, name the versions, and keep to Apple and CISA-style update practice. Related defensive context only: Apple out-of-bounds write CVE-2026-64769 fixed across iOS, iPadOS, macOS, tvOS, and visionOS builds listed on NVD with a July 2026 publish stamp; and macOS Tahoe 26.6.1’s Screen Sharing authentication fix CVE-2026-65400 dated 6 August in the public record.
Defensive frame, and I mean the word. CVE-2026-43748 sits in Apple’s Neural Engine driver. The public severity is CVSS 9.8. The public class language is out-of-bounds write from a sandboxed application context. That is as far as the mechanics go here. Sandbox escape class names are urgency signals for patch managers. They are not a licence to reprint a researcher’s trigger. If you need the bug’s shape, read Apple’s security update page for the fixed builds. If you need a weekend project, update the fleet.
Versions that matter on the 3 September 2026 SecurityOnline packet: macOS Sequoia 15.7.8, macOS Tahoe 26.6, and the matching iOS builds Apple shipped in the same remediation family. Install those. Verify the build string on a sample of Macs and phones. Close the change with CVE-2026-43748 in the ticket title. That is the entire actionable core. Everything else is context so you do not confuse this CVE with the neighbouring Apple fixes from the same season.
No confirmed in-the-wild exploitation, per SecurityOnline on 3 September 2026, is a factual clause — not a reason to wait. KEV is the catalogue for evidenced exploitation. Absence from that kind of confirmation still leaves you with a CVSS 9.8 driver bug and vendor fixed builds. Patch on the vendor’s schedule, not on a threat actor’s press cycle. CISA-style practice for high-severity vendor fixes is the same habit whether or not a CVE has hit KEV yet: inventory, update, verify.
Researchers published a proof of concept. I’m stating that fact once so nobody thinks I’m hiding the existence of public research. I’m not describing the PoC. I’m not quoting crash logs. I’m not listing syscalls, IOKit selectors, or model-input shapes. I’m not telling you which sample app to sideload. PoC existence raises urgency for defenders who patch slowly. PoC detail in a newspaper raises urgency for the wrong reader. I’m choosing the first reading.
Related Apple OOB write, July 2026 on NVD: CVE-2026-64769. Fixed across iOS, iPadOS, macOS, tvOS, and visionOS builds as listed on the NVD record. Same broad lesson — out-of-bounds write class, vendor fixed builds across the Apple OS family — without turning two CVEs into one mushy blob. If your estate still has devices that missed the mid-year wave, the NVD page is the checklist. I’m not inventing build numbers beyond what you should confirm on NVD and Apple support for the devices you actually hold.
Tahoe point release with a different job: macOS Tahoe 26.6.1 addressed Screen Sharing authentication under CVE-2026-65400, with a 6 August public stamp in the materials cited here. Authentication fix on Screen Sharing is not the Neural Engine driver story. It is neighbouring hygiene on the same major release train. If you jumped to 26.6 for CVE-2026-43748, check whether 26.6.1 is the build your Macs should actually carry so Screen Sharing authentication is in the same breath as the Neural Engine fix. Read Apple’s notes; do not assume two CVEs share one installer without checking.
The countable lines. CVE-2026-43748 — Apple Neural Engine driver — CVSS 9.8 — out-of-bounds write from sandboxed app (public class language only). Fixed examples on the SecurityOnline 3 September 2026 summary: macOS Sequoia 15.7.8, macOS Tahoe 26.6, matching iOS. In-the-wild: no confirmed exploitation on that reporting. PoC: exists; not described here. Related: CVE-2026-64769 OOB write, NVD July 2026, fixed across iOS/iPadOS/macOS/tvOS/visionOS builds listed there. Related: CVE-2026-65400 Screen Sharing auth, macOS Tahoe 26.6.1, 6 August. Sources: SecurityOnline, NVD, Apple support.
How a Mac admin runs the week without turning into a researcher. Pull Apple’s security content page for Sequoia 15.7.8 and Tahoe 26.6 / 26.6.1. Map every Mac and managed iPhone against those builds in your MDM. Force the update ring. Block deferrals on the security payloads if your MDM allows it. Recheck a sample with sw_vers on Mac and Settings → General → About on iOS. Log the CVE IDs against the asset groups. That is update practice. That is what “Apple patched the Neural Engine” means operationally.
What I will not do, restated because this beat attracts the wrong ask. I will not reconstruct the PoC from memory. I will not describe how a sandboxed app reaches the Neural Engine driver surface. I will not give “safe reproduction” steps. There is no safe reproduction paragraph in a public hacking piece for a CVSS 9.8 driver write. Vendor patch. MDM compliance. Done.
Put this next to the Chromium KEV energy of the same week without confusing the instruments. KEV entries carry evidenced exploitation and federal BOD clocks. CVE-2026-43748, on SecurityOnline’s 3 September telling, did not come with confirmed in-the-wild exploitation. Different urgency grammar. Same patch reflex. Browser KEV and Apple driver fixes can share a standup without sharing a catalogue row.
Sandbox framing for managers who do not write drivers. “From a sandboxed app” in the public description means the bug class matters even when the user did not grant a full TCC farm of permissions. That is why you do not wait for a phishing narrative before you push 15.7.8 or 26.6. The vendor already decided the severity was 9.8. Your job is the build string, not a debate about whether your users open strange apps.
Apple support pages remain the canonical fixed-build list when a secondary wire summarises. SecurityOnline on 3 September 2026 is the peg for this piece’s version examples and the no-confirmed-exploitation clause. NVD is the peg for CVE-2026-64769’s July 2026 publish and multi-OS fixed list. The 6 August stamp on CVE-2026-65400 is the peg for Tahoe 26.6.1 Screen Sharing authentication. If Apple’s support matrix later adds another point release, the support matrix wins.
Fleet reality check. Creative Macs with Neural Engine workloads, developer laptops on Tahoe betas that somehow missed a security train, and executive iPhones on delayed iOS rings are the usual stragglers. Name an owner for each ring before the standup ends. CVE-2026-43748 is not a philosophical discussion about on-device AI. It is a driver update. Treat it like one.
Apple patched the Neural Engine. CVE-2026-43748, CVSS 9.8, out-of-bounds write from a sandboxed app on the public description, fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6, and matching iOS per SecurityOnline 3 September 2026. No confirmed in-the-wild exploitation on that reporting. PoC exists and is not described here. Related defensive notes: CVE-2026-64769 across Apple OS family builds on NVD (July 2026), and CVE-2026-65400 Screen Sharing authentication in Tahoe 26.6.1 (6 August). Sources: SecurityOnline, NVD, Apple support. Patch now. Name the versions. Leave the trigger alone.






The paper
Comments
No notes on this story yet.
Sign in to comment