DIRAS TAKE
Urgently update devices: public exploit code is available, so apply the 26.6 updates promptly to reduce risk.
What is CVE-2026-43813?
A maliciously crafted app can bypass code signing enforcement on Apple iOS and iPadOS, potentially allowing unsigned or tampered code to execute on affected devices; this is tracked as CVE-2026-43813. The flaw affects iOS and iPadOS 26.x before 26.6 (and related Apple platforms listed below) and requires a malicious app to be installed and run by the user. Apple fixed the issue in 26.6 releases for the affected platforms. An attacker needs to deliver and get a user to run the crafted app to exploit the vulnerability.
Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Which versions of Apple iOS and iPadOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 26.x | before 26.6 | 26.6 |
| macOS 26.x | before 26.6 | 26.6 |
| tvOS 26.x | before 26.6 | 26.6 |
| visionOS 26.x | before 26.6 | 26.6 |
| watchOS 26.x | before 26.6 | 26.6 |
Is CVE-2026-43813 being exploited?
Public exploit code is available.
How to fix CVE-2026-43813
- Install the vendor updates: upgrade iOS/iPadOS devices to 26.6 (also update macOS, tvOS, visionOS, watchOS to 26.6 where applicable).
- Prevent installation of untrusted apps and restrict device enrollment or sideloading where possible.
- Monitor device behavior and app installation logs for unexpected or unsigned app activity.
- Follow vendor guidance and apply additional configuration or app store restrictions recommended by Apple.
Frequently asked questions
Is CVE-2026-43813 being actively exploited?
Public exploit code for CVE-2026-43813 is available.
Which iOS and iPadOS versions are affected by CVE-2026-43813?
iOS and iPadOS 26.x versions before 26.6 are affected; Apple also lists fixes in macOS, tvOS, visionOS, and watchOS 26.6.
Is there a patch for CVE-2026-43813?
Yes. Apple fixed the issue in 26.6 releases for iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
Does CVE-2026-43813 require authentication?
No privileged account is required, but exploitation requires a user to install and run a maliciously crafted app.
References
- nvd.nist.gov/vuln/detail/CVE-2026-43813
- cve.org/CVERecord?id=CVE-2026-43813
- support.apple.com/en-us/128066
- support.apple.com/en-us/128067
- support.apple.com/en-us/128068
- support.apple.com/en-us/128069
- support.apple.com/en-us/128070
- All Apple CVEs on CVE Radar
- CVEs published in September 2026