Junglewise Threat Intelligence

CVE-2026-43723: Apple Multiple Operating Systems privilege escalation in path handling

CVE-2026-43723 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability in Apple operating systems, including iOS, macOS, and watchOS, could allow a malicious application to gain full administrative (root) control over a device. This level of access would allow an attacker to bypass security protections, access sensitive user data, or modify system settings. Users should update their devices to the latest software versions to resolve this issue.

Technical details

A path handling vulnerability exists across multiple Apple platforms (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS) due to insufficient validation of file paths. A local malicious application can exploit this flaw to escalate its privileges to root. The vulnerability was addressed by implementing improved path validation logic. Affected versions include iOS/iPadOS before 26.6, macOS Sequoia before 15.7.8, macOS Sonoma before 14.8.8, and other platform versions prior to 26.6.

Affected products

  • Apple iOS and iPadOS < 26.6
  • Apple macOS Sequoia < 15.7.8
  • Apple macOS Sonoma < 14.8.8
  • Apple macOS Tahoe < 26.6
  • Apple tvOS < 26.6
  • Apple visionOS < 26.6
  • Apple watchOS < 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats