Junglewise Threat Intelligence

CVE-2026-43679: Apple watchOS FaceTime permissions bypass in contacts access

CVE-2026-43679 · Severity: low · CVSS 2.4 · Published 2026-08-21

Technologies: Apple watchOS. Vendors: Apple.

Executive brief

An attacker with physical access to a locked Apple Watch can view the device owner's contacts through a permissions vulnerability in the FaceTime component. This allows unauthorized access to personal contact information without needing to unlock the device or enter a passcode, potentially exposing phone numbers and contact details to someone with brief physical access.

Technical details

This is a permissions-checking vulnerability in the FaceTime component of watchOS that allows unauthorized access to user contacts. The vulnerability requires physical access to a locked Apple Watch; an attacker cannot remotely exploit this issue. The flaw was in the FaceTime application's permissions validation logic, which did not properly enforce access controls on the contacts database. An attacker with physical possession of the device can bypass the lock screen protections to enumerate and view stored contact information. Apple addressed the issue by implementing improved permissions checking in watchOS 26.4, released March 24, 2026.

Affected products

  • Apple watchOS before 26.4

Timeline

  • 2026-08-20: disclosed: Security advisory entry added
  • 2026-03-24: patched: Fixed in watchOS 26.4

References

Related threats