Junglewise Threat Intelligence

CVE-2026-43796: Apple multiple operating systems sensitive data access via improved data protection

CVE-2026-43796 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS Tahoe, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A security issue in Apple operating systems could allow a malicious application to access sensitive user data. This affects a wide range of devices including iPhones, iPads, Macs, and Apple Watches. If exploited, private information could be exposed to unauthorized apps installed on the device. Apple has released software updates to address this by improving data protection mechanisms.

Technical details

A vulnerability in Apple's data protection framework across multiple operating systems (iOS, macOS, tvOS, etc.) could allow a locally installed application to bypass intended restrictions and access sensitive user information. The root cause is related to insufficient data protection enforcement, which Apple addressed by hardening these mechanisms. An attacker would need to have an app running on the target device to exploit this flaw. The issue is resolved in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Affected products

  • Apple iOS Before 26.6
  • Apple iPadOS Before 26.6
  • Apple macOS Sequoia Before 15.7.8
  • Apple macOS Sonoma Before 14.8.8
  • Apple macOS Tahoe Before 26.6
  • Apple tvOS Before 26.6
  • Apple visionOS Before 26.6
  • Apple watchOS Before 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats