CVE-2026-43783(apple / macos)

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A race condition was addressed with improved locking. This issue is fixed in macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-362

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Affected systems

Vendors
Products
macos

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-15: 209-15
Referenced assets3 URLs
Full discourse2 posts
  • PT SWARM@ptswarm

    🍏 Fresh LPE in macOS: Repair Permissions - Get Root! CVE-2026-43783 found by our researcher Ilya Andr (@andrd3v) has been recently fixed by Apple. A single XPC request to DesktopServicesHelper lets you chown any path on disk - straight to root. 👇👇👇 https://ptswarm.com/blog/cve-2026-43783-repair-permissions-get-root-lpe-via-desktopserviceshelper-in-macos-26-5/ https://t.co/k77bElRYGM

    19045181.9K
    18.7K followersView on X
  • Ilya Andr@andrd3v

    Missed one more from the drop lol CVE-2026-43783 - macOS LPE via DesktopServicesHelper. One XPC request -> arbitrary chown -> root. PT SWARM writeup: https://ptswarm.com/blog/cve-2026-43783-repair-permissions-get-root-lpe-via-desktopserviceshelper-in-macos-26-5/ My blog: https://andrd3v.github.io/cve-2026-43783/index.html PoC: https://github.com/andrd3v/CVE-2026-43783

    11092497
    115 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---

Explore more