CVE-2026-43786(apple / macos)

LOWCVSS 7.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-280

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 3 mentions on most recent observed day (2026-09-22)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
macos

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-09-21: 1Mentions · 2026-09-22: 309-2109-22
Referenced assets3 URLs
Full discourse4 posts
  • Kağan IŞILDAK@kaganisildak

    Just dropped a PoC for CVE-2026-43786. Local privilege escalation to root through macOS CoreServices. Patched in Sequoia 15.8, Tahoe 26.7 and Golden Gate 27. https://github.com/Malwation/CVE-2026-43786 @malwation https://t.co/R26viUJ5oK

    7150143648.4K
    4.6K followersView on X
  • ThreatWire@ThreatWire_

    🚨 PoC RELEASED: A public PoC is now available for CVE-2026-43786, a macOS privilege-escalation vulnerability rated CVSS 7.8. The flaw could allow an app to gain root privileges due to insufficient entitlement checks. ⚠️ Affected macOS versions include releases prior to Sequoia 15.8, Tahoe 26.7 and Golden Gate 27. 🔴 Apple has addressed the issue with additional entitlement checks. Update macOS. 🔗 https://github.com/malwation/cve-2026-43786 #Apple #macOS #CVE #PoC #CyberSecurity #Infosec

    13081588
    1.5K followersView on X
  • Mr.Niko@_MrNiko

    🚨 CVE-2026-43786 macOS CoreServices local app to root. CVSS 7.8. Apple's line is short. an app may be able to gain root privileges. Malwation shipped the C PoC and a video of it landing. https://github.com/Malwation/CVE-2026-43786 #macOS #ExploitDev #InfoSec https://t.co/67LjbTHcCO

    02062396
    1.2K followersView on X
  • dbugs@ptdbugs

    A PoC/exploit has been discovered for vulnerability CVE-2026-43786 PT ID: PT-2026-91500 Vendor: Apple Product: macOS Description: This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges. References: • https://dbu.gs/vulnerability/PT-2026-91500 • https://github.com/malwation/cve-2026-43786

    00002245
    3.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---

Explore more