CVE-2026-43728
published 2026-07-27CVE-2026-43728: This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26.6. An attacker may be able to modify the state of the…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.19%
9.5th percentile
This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26.6. An attacker may be able to modify the state of the Keychain.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 26.6 | 26.6 |
| apple | macos | >= 26.0 < 26.6 | 26.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple macOS up to 26.5 Keychain state issue
vuldb·2026-07-28
CVE-2026-43728 Apple macOS up to 26.5 Keychain state issue
A vulnerability has been found in Apple macOS up to 26.5 and classified as very critical. The impacted element is an unknown function of the component Keychain. The manipulation leads to state issue.
This vulnerability is uniquely identified as CVE-2026-43728. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
GHSA
This issue was addressed through improved state management.
ghsa_unreviewed·2026-07-27
CVE-2026-43728 [HIGH] CWE-362 This issue was addressed through improved state management.
This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26.6. An attacker may be able to modify the state of the Keychain.
No detection rules found.
No public exploits indexed.
2026-07-27
Published