Junglewise Threat Intelligence

CVE-2026-43800: Apple OS information disclosure via malicious application

CVE-2026-43800 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS, Apple watchOS, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability in Apple operating systems could allow a malicious application to access sensitive user data. This affects iPhones, iPads, Macs, Apple TVs, and Apple Watches. Users should update to version 26.6 of their respective operating systems to protect their personal information.

Technical details

An information disclosure vulnerability exists across multiple Apple operating systems, including iOS, iPadOS, macOS, tvOS, and watchOS. The flaw allows a locally installed application to bypass intended data protections and access sensitive user information. Apple addressed the issue by removing the vulnerable code in the 26.6 updates for all affected platforms. While specific technical details of the root cause were not disclosed, the fix involved the removal of the problematic code path. Exploitation requires a malicious app to be present on the device.

Affected products

  • Apple iOS and iPadOS < 26.6
  • Apple macOS Tahoe < 26.6
  • Apple tvOS < 26.6
  • Apple watchOS < 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats