• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-43786: privilege escalation in Apple macOS

Local attackers can gain root privileges on macOS through insufficient entitlement checks; this is tracked as CVE-2026-43786. The flaw affects macOS Sequoia 15.x before 15.8, macOS Tahoe 26.x before 26.7, and macOS Golden Gate 27.x before 27, and requires local access with low privileges (no user interaction).

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.8HIGH
EPSS
0.00154
CWE
CWE-280
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so prioritize updates — Apple released fixes in 15.8, 26.7, and 27. Apply patches quickly for any systems with local untrusted users.

What is CVE-2026-43786?

Local attackers can gain root privileges on macOS through insufficient entitlement checks; this is tracked as CVE-2026-43786. The flaw affects macOS Sequoia 15.x before 15.8, macOS Tahoe 26.x before 26.7, and macOS Golden Gate 27.x before 27, and requires local access with low privileges (no user interaction).

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple macOS are affected?

BRANCHAFFECTEDFIXED
15.xbefore 15.815.8
26.xbefore 26.726.7
27.xbefore 2727

Is CVE-2026-43786 being exploited?

Public exploit code is available.

How to fix CVE-2026-43786

  1. Install the vendor fixes: update macOS to 15.8, 26.7, or 27 as appropriate.
  2. If immediate patching is not possible, remove or restrict local untrusted accounts and restrict physical or remote local access.
  3. Monitor system logs for unexpected privilege changes and suspicious local process activity.
  4. Follow Apple's guidance and verify devices are running the fixed builds after updating.

Frequently asked questions

Is CVE-2026-43786 being actively exploited?

Public exploit code is available for CVE-2026-43786.

Which macOS versions are affected by CVE-2026-43786?

macOS Sequoia 15.x before 15.8, macOS Tahoe 26.x before 26.7, and macOS Golden Gate 27.x before 27 are affected.

Is there a patch for CVE-2026-43786?

Yes — Apple fixed the issue in macOS Sequoia 15.8, macOS Tahoe 26.7, and macOS Golden Gate 27.

Does CVE-2026-43786 require authentication?

It requires local access with low privileges (no additional user interaction), not prior administrative authentication.

References