Double-free Vulnerability in BoringSSL Public Key Initialization in Swift Crypto
CVE-2026-43823

Currently unrated

Key Information:

Vendor

Apple

Vendor
CVE Published:
23 July 2026

What is CVE-2026-43823?

A severe double-free vulnerability occurs during the initialization of an RSA public key from DER or PEM bytes in Swift Crypto. This issue arises when BoringSSL encounters a failure to decode the public key from the provided byte data, leading to the EVP_PKEY structure being incorrectly freed twice. Such improper memory management can result in application crashes during subsequent memory allocations. The vulnerability has been rectified in Swift Crypto version 4.5.1, which addresses the issue to enhance the security and stability of the software.

Affected Version(s)

swift-crypto 0 < 4.5.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.