Junglewise Threat Intelligence

CVE-2026-43728: Apple macOS Tahoe state management vulnerability in Keychain

CVE-2026-43728 · Severity: info · CVSS 0 · Published 2026-07-27

Technologies: Apple macOS. Vendors: Apple.

Executive brief

Apple macOS Tahoe contains a vulnerability in the Keychain, the system used to securely store passwords and sensitive account information. An attacker with access to the system could potentially modify the state of the Keychain, which could lead to unauthorized changes to stored credentials or security settings. This issue has been resolved in macOS Tahoe 26.6.

Technical details

A vulnerability in macOS Tahoe's Keychain component was caused by improper state management. An attacker with local access may be able to modify the internal state of the Keychain, potentially impacting the integrity of stored secrets or the security posture of the credential management system. The issue was addressed by Apple through improved state management logic. The vulnerability is fixed in macOS Tahoe version 26.6.

Affected products

  • Apple macOS Tahoe before 26.6

Timeline

  • 2026-07-27: disclosed: Initial disclosure by Apple
  • 2026-07-27: patched: Fixed in macOS Tahoe 26.6

References

Related threats