CVE-2026-43805 is a race condition vulnerability in Apple operating systems that was addressed through improved state handling. The flaw affects iOS, iPadOS, macOS, and watchOS prior to the fixed releases and allows a local application to trigger unsafe concurrent state transitions that can result in unexpected system termination or modification of kernel memory. The available information indicates the issue resides in kernel-adjacent or privileged state management rather than a userland-only logic flaw, creating the possibility of destabilizing the operating system or corrupting sensitive memory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This 41-file repository is a proof-of-concept and root-cause analysis for CVE-2026-43805, an alleged local IOKit race in IODMACommand::PerformOperation_Impl. Its analysis concludes that vulnerable builds check fActive and later use fMemory without holding fDextLock, while CompleteDMA can acquire that lock, clear the prepared DMA state, and release the memory descriptor. The claimed fix serializes PerformOperation, PrepareForDMA, and CompleteDMA using fDextLock. The repository has three primary components. poc/model/race_model.cpp is a portable C++20 deterministic concurrency model, built via `make model`; it deliberately schedules the stale-memory interleaving in the vulnerable design and verifies locking prevents it in the modeled fixed design. poc/apple-driverkit-sample is a modified Apple DriverKit user-client sample containing a Swift macOS app, C IOKit client code, and a NullDriver DriverKit extension. The app calls selector 6 with 10,000 iterations and a 1 MiB buffer. The extension creates two independent DriverKit dispatch queues: an operation worker performs IODMACommand::PerformOperation with the Zero option while a lifecycle worker repeatedly calls CompleteDMA followed by PrepareForDMA on the same command. It is intended to widen and exercise the time-of-check/time-of-use window. The tools directory contains Python/Capstone utilities to selectively extract files from Apple PBZX/CPIO KDK payloads, parse x86_64 Mach-O symbol tables, compare normalized function disassembly, and disassemble a selected symbol with resolved direct calls. Documentation records a comparison of macOS KDK 26.5 and 26.6 kernels and identifies added IOLockLock/IOLockUnlock calls around PerformOperation_Impl. The native DriverKit trigger was explicitly not built or run on a vulnerable Apple host by the repository author; therefore, it remains an unverified crash/race trigger rather than a demonstrated reliable kernel-write exploit. It has no command shell, persistence, remote-control capability, or network communication.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.