CVE-2026-43792
published 2026-07-27CVE-2026-43792: An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to access…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.25%
16.3th percentile
An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 26.6 | 26.6 |
| apple | macos | >= 26.0 < 26.6 | 26.6 |
| apple | safari | < 26.6 | 26.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple macOS/Safari up to 26.5 improper authorization
vuldb·2026-07-28
CVE-2026-43792 [LOW] Apple macOS/Safari up to 26.5 improper authorization
A vulnerability identified as problematic has been detected in Apple macOS and Safari up to 26.5. This affects an unknown part. The manipulation leads to improper authorization.
This vulnerability is listed as CVE-2026-43792. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
GHSA
An authorization issue was addressed with improved state management.
ghsa_unreviewed·2026-07-27
CVE-2026-43792 [MEDIUM] CWE-285 An authorization issue was addressed with improved state management.
An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.
No detection rules found.
No public exploits indexed.
2026-07-27
Published