• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-43783: privilege escalation in Apple macOS

A local, low-privileged app can exploit a race condition to gain root on macOS (CVE-2026-43783). The flaw affects macOS 26.x releases before 26.6 and requires local code execution by a malicious app; no interactive user approval is required. Apple fixed the issue in macOS 26.6 and public exploit code is available, increasing risk for unpatched systems.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.8HIGH
EPSS
0.00129
CWE
CWE-362
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: install macOS 26.6 immediately because public exploit code exists and the vulnerability allows a local unprivileged app to escalate to root.

What is CVE-2026-43783?

A local, low-privileged app can exploit a race condition to gain root on macOS (CVE-2026-43783). The flaw affects macOS 26.x releases before 26.6 and requires local code execution by a malicious app; no interactive user approval is required. Apple fixed the issue in macOS 26.6 and public exploit code is available, increasing risk for unpatched systems.

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple macOS are affected?

BRANCHAFFECTEDFIXED
26.xbefore 26.626.6

Is CVE-2026-43783 being exploited?

Public exploit code is available.

How to fix CVE-2026-43783

  1. Upgrade affected systems to macOS 26.6 (contains the fix).
  2. Block or restrict installation of untrusted local applications and enforce application whitelisting where possible.
  3. Monitor for signs of local privilege escalation and review system logs for unexpected root activity.
  4. Follow Apple's advisory and update guidance for any additional remediation steps.

Frequently asked questions

Is CVE-2026-43783 being actively exploited?

Public exploit code is available for CVE-2026-43783, and it is not listed in CISA's Known Exploited Vulnerabilities catalog as of 2026-09-29.

Which macOS versions are affected by CVE-2026-43783?

macOS 26.x releases before 26.6 are affected; Apple fixed the issue in macOS 26.6.

Is there a patch for CVE-2026-43783?

Yes, Apple released a fix in macOS 26.6.

What can an attacker do with CVE-2026-43783?

A local attacker controlling a low-privileged app can exploit the race condition to obtain root privileges on macOS.

References