CVE-2026-43663

Overview

Advisory: Apple Security Advisory

Impact:

Description: Processing maliciously crafted web content may lead to an unexpected process crash

Researchers: Using GLM From Z.AI, Tristan Madani (@TristanInSec) from Talence Security, stratan (@5tratan) of Almamater Technologies, Soyeon Park, Amy Burnett, Khai Tran, sherkito, Kota Toda, HexRabbit (@h3xr4bb1t) and NiNi (@terrynini38514) of DEVCORE Research Team, Brian Carpenter

Attribute Value
CVE CVE-2026-43663
Bugzilla 312781
Component JSC
Bug Class LogicError
Severity medium
Commit 13bfbf94f49eab45…
Advisory Apple Advisory

Root Cause Analysis

The issue was addressed with improved memory handling.

Files Changed

Source Files

  • Source/JavaScriptCore/dfg/DFGConstantFoldingPhase.cpp

Test Files

  • JSTests/stress/resizable-array-constant-folding.js