Junglewise Threat Intelligence

CVE-2026-43783: Apple macOS race condition privilege escalation in account handling

CVE-2026-43783 · Severity: high · CVSS 7.8 · Published 2026-09-14

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A race condition in Apple macOS account handling could allow a malicious application to gain root-level privileges on an affected system. Root access provides unrestricted control over the device and all user data, representing a complete compromise of system security and confidentiality.

Technical details

A race condition vulnerability exists in macOS account handling logic, addressed through improved locking mechanisms. The vulnerability allows a local malicious application to exploit a timing window between state checks and state modifications, leading to privilege escalation to root. This requires a malicious app to be installed and executed on the target system. The issue is fixed in macOS Tahoe 26.6 (released July 27, 2026), which implements improved synchronization and locking to prevent the race condition.

Affected products

  • Apple macOS Tahoe before 26.6

Timeline

  • 2026-09-14: disclosed: CVE-2026-43783 published
  • 2026-07-27: patched: Fixed in macOS Tahoe 26.6

References

Related threats