Junglewise Threat Intelligence

CVE-2026-43797: Apple iOS and macOS information disclosure in Contacts

CVE-2026-43797 · Severity: info · Published 2026-07-27

Technologies: Apple macOS, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability in Apple's mobile and desktop operating systems could allow a malicious application to access a user's private contact information without proper authorization. This affects iPhones, iPads, and Mac computers running older versions of their respective software. If exploited, this could lead to the unauthorized collection of personal data, potentially impacting user privacy and corporate data confidentiality.

Technical details

A privacy issue exists in Apple iOS, iPadOS, and macOS Tahoe where an application could bypass intended restrictions to access user contact information. The vulnerability stems from insufficient validation checks within the operating system's permission framework. A local attacker could exploit this by convincing a user to install a malicious app, which could then programmatically query and exfiltrate contact data. Apple addressed this issue in iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6 by implementing improved checks.

Affected products

  • Apple iOS before 26.6
  • Apple iPadOS before 26.6
  • Apple macOS Tahoe before 26.6

Timeline

  • 2026-07-27: advisory: Initial advisory published by Apple and NVD
  • 2026-07-27: patched: Fixed in iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6

References

Related threats