Junglewise Threat Intelligence

CVE-2026-43696: Apple macOS authorization bypass in Touch Bar access

CVE-2026-43696 · Severity: medium · CVSS 5.3 · Published 2026-09-14

Technologies: Apple macOS, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

macOS includes a Touch Bar interface that displays sensitive contextual information on compatible Mac keyboards. A flaw in authorization controls allowed unauthorized apps to capture Touch Bar content without user permission or awareness, potentially exposing sensitive data like passwords, payment information, or personal details displayed in that interface. This issue is fixed in macOS Golden Gate 27.

Technical details

An authorization issue in macOS permitted applications to access Touch Bar content without proper entitlement verification. The vulnerability stems from insufficient entitlement checks that should gate which apps can capture or read Touch Bar display data. An attacker who can execute a malicious app on the target system can bypass authorization prompts and exfiltrate sensitive information displayed on the Touch Bar without user knowledge or consent. No user interaction is required beyond initial app installation. The vulnerability is patched in macOS Golden Gate 27 released September 14, 2026.

Affected products

  • Apple macOS Golden Gate prior to 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in macOS Golden Gate 27

References

Related threats