Junglewise Threat Intelligence

CVE-2026-43689: Apple iOS permissions issue allowing root privilege escalation

CVE-2026-43689 · Severity: high · CVSS 7.8 · Published 2026-09-14

Technologies: Apple macOS, Apple macOS Golden Gate, Apple Iphone Os, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A permissions flaw in iOS, iPadOS, macOS, and visionOS could allow a malicious app installed on an Apple device to gain root-level system access. This represents a critical security risk, as root access enables an attacker to completely control the device, access all user data, install persistent malware, and bypass all security protections. The vulnerability affects a broad range of Apple devices and requires a fix that users must install promptly.

Technical details

A permissions issue in Apple's operating systems was addressed through additional access restrictions in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, and visionOS 27. The root cause involves improper enforcement of privilege boundaries, allowing a local malicious app to escalate from user context to root privileges. Attack vector is local and requires only that a malicious app be installed on the device; no network access or additional user interaction is needed. An attacker exploiting this can achieve complete system compromise. Patches are available in the listed OS versions and should be applied immediately.

Affected products

  • Apple iOS 26.7, 27
  • Apple iPadOS 26.7, 27
  • Apple macOS Golden Gate 27
  • Apple visionOS 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-43689 disclosed; fixes released in iOS 27, iPadOS 27, macOS Golden Gate 27, visionOS 27
  • 2026-09-14: patched: Fixed in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, visionOS 27

References

Related threats