Junglewise Threat Intelligence

CVE-2026-43791: Apple macOS input validation in file access

CVE-2026-43791 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

macOS is Apple's operating system used on Macintosh computers. A validation flaw allows applications to read arbitrary files on the system by bypassing intended access controls. Attackers could exploit this to steal sensitive data such as documents, credentials, or personal information stored on the computer.

Technical details

A validation issue in macOS allows an app to read arbitrary files on the system due to insufficient input sanitization. The vulnerability exists in the file access control logic and has been addressed through improved input validation. The attack requires a malicious or compromised app to be present on the system; exploitation occurs at the local level without requiring elevated privileges or network access. An attacker can leverage this to access files outside intended sandbox boundaries or bypass path restrictions, leading to unauthorized file disclosure. The issue is patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate prior to 27
  • Apple macOS Sequoia prior to 15.8
  • Apple macOS Tahoe prior to 26.7

Timeline

  • 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7
  • 2026-09-14: disclosed

References

Related threats