Junglewise Threat Intelligence

CVE-2026-43652: Apple macOS Tahoe permissions bypass in Privacy preferences

CVE-2026-43652 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A security vulnerability in macOS Tahoe could allow a malicious application to bypass privacy protections and access sensitive user data. This could result in the unauthorized exposure of personal information stored on the device. Users should update to macOS Tahoe 26.5 to resolve this issue and ensure their data remains protected.

Technical details

A permissions issue in macOS Tahoe was identified where applications could bypass established privacy preferences to access protected user data. The vulnerability stems from insufficient restrictions within the operating system's authorization framework. An attacker could exploit this by tricking a user into running a malicious application, which would then gain unauthorized access to sensitive information. Apple addressed this flaw in macOS Tahoe 26.5 by implementing additional permission restrictions and improving state management. The issue is tracked as CVE-2026-43652.

Affected products

  • Apple macOS Tahoe Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched: Fixed in macOS Tahoe 26.5

References

Related threats