CVE-2026-43689

Summary

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. A malicious app may be able to gain root privileges.

Affected Software

VendorProductVersion RangeStatus
AppleiOS and iPadOS0 < 26.7affected
AppleiOS and iPadOS0 < 27affected
ApplemacOS0 < 27affected
ApplevisionOS0 < 27affected

Weaknesses

  • A malicious app may be able to gain root privileges

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References