CVE-2026-43663
Overview
Advisory: Apple Security Advisory
Impact:
Description: Processing maliciously crafted web content may lead to an unexpected process crash
Researchers: Using GLM From Z.AI, Tristan Madani (@TristanInSec) from Talence Security, stratan (@5tratan) of Almamater Technologies, Soyeon Park, Amy Burnett, Khai Tran, sherkito, Kota Toda, HexRabbit (@h3xr4bb1t) and NiNi (@terrynini38514) of DEVCORE Research Team, Brian Carpenter
| Attribute | Value |
|---|---|
| CVE | CVE-2026-43663 |
| Bugzilla | 312781 |
| Component | JSC |
| Bug Class | LogicError |
| Severity | medium |
| Commit | 13bfbf94f49eab45… |
| Advisory | Apple Advisory |
Root Cause Analysis
The issue was addressed with improved memory handling.
Files Changed
Source Files
Source/JavaScriptCore/dfg/DFGConstantFoldingPhase.cpp
Test Files
JSTests/stress/resizable-array-constant-folding.js