Executive brief
An app may be able to modify files that it only had permission to read on affected Apple devices. This permissions flaw could allow an installed app to alter user data or system files it shouldn't have write access to, potentially compromising data integrity and system stability across iPhones, iPads, and Mac computers.
Technical details
CVE-2026-43785 is a permissions issue in Apple's iOS and macOS operating systems where file access controls are insufficiently enforced. The vulnerability allows a locally installed app to gain write access to files for which it only has read permissions. The vulnerability is addressed through additional restrictions and improved access control validation. This is a local attack vector requiring the attacker to have an app installed on the target device. The issue affects iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, and visionOS 27, with patches available in these versions.
Affected products
- Apple iOS 27
- Apple iPadOS 27
- Apple macOS Golden Gate 27
- Apple macOS Sequoia 15.8
- Apple macOS Tahoe 26.7
- Apple tvOS 27
- Apple visionOS 27
Timeline
- 2026-09-14: disclosed: CVE-2026-43785 published and patched in iOS 27, iPadOS 27, macOS Golden Gate 27, and other versions