CVE-2026-43760Disclosure(apple / macos)

LOWCVSS 8.6 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch apple macos systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may be able to access user-sensitive data.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-08-17)
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
macos

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-08-04: 1Mentions · 2026-08-09: 2Mentions · 2026-08-17: 4Patch / Workaround · 2026-08-17: 3Technical Details · 2026-08-09: 2Technical Details · 2026-08-17: 308-0408-0908-17
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
General
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-041
General1
2026-08-092
Disclosure2
2026-08-174
Disclosure2Patch2
Full discourse7 posts
  • Dr. Mazin Al-Busaidi@mazin_dr38737
    Disclosure

    🚨 macOS Security Alert! 🚨 A critical logic flaw in Apple’s Screen Sharing (CVE-2026-43760) could allow attackers to gain full ROOT command execution. The vulnerability resides in how the screensharingd service handles file-copy operations. While native Apple authentication is secure, using the legacy VNC password option creates a dangerous loophole. Attackers can exploit this discrepancy to bypass standard permission checks and run commands with elevated privileges. If you have Screen Sharing or Remote Management enabled, audit your settings immediately! Disabling legacy VNC passwords is a key step to staying protected. Stay safe, stay updated! 💻🛡️ #macOS #CyberSecurity #Apple #Infosec #TechNews #cybersecuritynews

    Post summary

    The post announces a critical logic flaw (CVE‑2026‑43760) in macOS Screen Sharing that can grant root execution via legacy VNC passwords, and recommends disabling these passwords as a mitigation.

    080100246
    1.1K followersView on X
  • National CERT/CC@CERT_UG
    Patch

    🚨 Patch Now | August 17, 2026 Bringing these CVE's and mitigations to your attention. - Apple macOS Screen Sharing (CVE-2026-43760) - VMware vCenter (CVE-2026-59310) - Windows Server 2022: 60 days to end of mainstream support. https://cert.ug | #CyberSafeUG https://t.co/7ulsZjBOpG

    Post summary

    The tweet alerts readers to CVE-2026-43760 and CVE-2026-59310 and urges patching or mitigation, but provides no further technical or exploitation details.

    02060175
    1.5K followersView on X
  • tpx Security ⠠⠵@tpx_Security
    Patch

    Investigadores hallaron el fallo lógico CVE-2026-43760 en Compartir Pantalla de macOS. Al usar autenticación VNC heredada, los procesos de transferencia de archivos se ejecutan como root, permitiendo a un atacante remoto obtener control total del sistema sin contraseña. Apple corrigió la falla en sus actualizaciones de julio de 2026.

    Post summary

    Investigadores identificaron CVE-2026-43760 en Screen Sharing de macOS, donde la autenticación VNC heredada permite a un atacante remoto ejecutar procesos como root. Apple publicó un parche en las actualizaciones de julio de 2026.

    00020271
    3.8K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    Critical macOS Screen Sharing Flaw Enables Pre-Auth RCE and Root File Access https://cyberpress.org/critical-macos-screen-sharing-flaw/ "CVE-2026-65400 follows closely on the heels of CVE-2026-43760, a separate Screen Sharing bug disclosed in late July."

    Post summary

    The linked article announces a critical macOS Screen Sharing flaw (CVE-2026-65400) that permits pre-authenticated remote code execution and root-level file access, and notes a related July CVE.

    10000243
    3.5K followersView on X
  • ThreadLinqs@threadlinqs
    Disclosure

    Got a Mac's VNC password? CVE-2026-43760 turns that into a root shell via a rigged sudoers file. https://intel.threadlinqs.com/threat/TL-2026-2038 #ThreatIntel #CVE_2026_43760 #navi_the_clown #VNC https://t.co/ezc9VMNsWw

    Post summary

    The tweet announces CVE‑2026‑43760, a macOS VNC password exploitation that gains root access through a tampered sudoers file, but provides no proof‑of‑concept details, patch information, or evidence of live attacks.

    0000051
    133 followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    Critical macOS RCE Vulnerability Allows Attackers to Gain Root Access Without Password https://gbhackers.com/critical-macos-rce-vulnerability/ "CVE-2026-65400 arrives close behind CVE-2026-43760, a separate Screen Sharing bug disclosed in late July."

    Post summary

    The post announces a new critical macOS RCE CVE‑2026‑65400 that enables attackers to obtain root access without credentials, without providing a PoC, exploit tool, or patch.

    00000175
    3.5K followersView on X
  • Lagoon Labs@LagoonLabsMv
    General

    Apple capped security reports after AI flood. Bynario used GPT-5.5 to find 50+ macOS bugs in 3 weeks - one real (CVE-2026-43760) but hit the cap and couldn't report it. The limit doesn't distinguish AI slop from real AI-found flaws. https://t.co/8GDVHRCaw2

    Post summary

    The tweet notes that AI-generated bug hunting yielded a real CVE‑2026‑43760 but was capped by Apple’s reporting limit; it lacks technical details, PoC, or exploitation evidence.

    0000053
    74 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---

Explore more