Junglewise Threat Intelligence

CVE-2026-43659: Apple FileProvider race condition allows sensitive data access

CVE-2026-43659 · Severity: medium · CVSS 4.7 · Published 2026-05-11

Technologies: Apple Visionos, Apple macOS Sonoma, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability exists in the FileProvider component of Apple operating systems, which manages how apps access and share files. A malicious application installed on a device could exploit a timing error to bypass security controls and access sensitive user information. This could lead to the unauthorized exposure of personal data stored on iPhones, iPads, and Macs.

Technical details

A race condition vulnerability exists within the FileProvider framework across multiple Apple operating systems (iOS, iPadOS, macOS, and visionOS). The flaw stems from inadequate validation during concurrent operations, which can be exploited by a local malicious application to bypass intended access restrictions. By winning the race condition, an attacker can gain unauthorized access to sensitive user data managed by the FileProvider. Apple addressed the issue by implementing additional validation logic to ensure state consistency during file operations. Patches are available in iOS/iPadOS 18.7.9 and 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, and visionOS 26.5.

Affected products

  • Apple iOS 18.7.9, 26.5
  • Apple iPadOS 18.7.9, 26.5
  • Apple macOS Sequoia 15.7.7
  • Apple macOS Sonoma 14.8.7
  • Apple macOS Tahoe 26.5
  • Apple visionOS 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats