• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-43813: code signing bypass in Apple iOS and iPadOS

A maliciously crafted app can bypass code signing enforcement on Apple iOS and iPadOS, potentially allowing unsigned or tampered code to execute on affected devices; this is tracked as CVE-2026-43813. The flaw affects iOS and iPadOS 26.x before 26.6 (and related Apple platforms listed below) and requires a malicious app to be installed and run by the user. Apple fixed the issue in 26.6 releases for the affected platforms. An attacker needs to deliver and get a user to run the crafted app to exploit the vulnerability.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.1HIGH
EPSS
0.00167
CWE
CWE-20
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgently update devices: public exploit code is available, so apply the 26.6 updates promptly to reduce risk.

What is CVE-2026-43813?

A maliciously crafted app can bypass code signing enforcement on Apple iOS and iPadOS, potentially allowing unsigned or tampered code to execute on affected devices; this is tracked as CVE-2026-43813. The flaw affects iOS and iPadOS 26.x before 26.6 (and related Apple platforms listed below) and requires a malicious app to be installed and run by the user. Apple fixed the issue in 26.6 releases for the affected platforms. An attacker needs to deliver and get a user to run the crafted app to exploit the vulnerability.

Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 26.xbefore 26.626.6
macOS 26.xbefore 26.626.6
tvOS 26.xbefore 26.626.6
visionOS 26.xbefore 26.626.6
watchOS 26.xbefore 26.626.6

Is CVE-2026-43813 being exploited?

Public exploit code is available.

How to fix CVE-2026-43813

  1. Install the vendor updates: upgrade iOS/iPadOS devices to 26.6 (also update macOS, tvOS, visionOS, watchOS to 26.6 where applicable).
  2. Prevent installation of untrusted apps and restrict device enrollment or sideloading where possible.
  3. Monitor device behavior and app installation logs for unexpected or unsigned app activity.
  4. Follow vendor guidance and apply additional configuration or app store restrictions recommended by Apple.

Frequently asked questions

Is CVE-2026-43813 being actively exploited?

Public exploit code for CVE-2026-43813 is available.

Which iOS and iPadOS versions are affected by CVE-2026-43813?

iOS and iPadOS 26.x versions before 26.6 are affected; Apple also lists fixes in macOS, tvOS, visionOS, and watchOS 26.6.

Is there a patch for CVE-2026-43813?

Yes. Apple fixed the issue in 26.6 releases for iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.

Does CVE-2026-43813 require authentication?

No privileged account is required, but exploitation requires a user to install and run a maliciously crafted app.

References