CVE-2026-43740

Overview

Advisory: Apple Security Advisory

Impact:

Description: Processing maliciously crafted web content may result in the disclosure of process memory

Researchers: Arni Hardarson, Nathaniel Oh (@calysteon)

Attribute Value
CVE CVE-2026-43740
Bugzilla 308046
Component JSC
Bug Class LogicError
Severity medium
Commit 2693828e8d7300d8…
Advisory Apple Advisory

Root Cause Analysis

The issue was addressed with improved memory handling.

Files Changed

Source Files

  • Source/JavaScriptCore/yarr/YarrJIT.cpp

Test Files

  • JSTests/stress/regexp-backreference-unicode-offset.js