CVE-2026-43797
published 2026-07-27CVE-2026-43797: This issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6. An app may be able to access information…
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.12%
2.2th percentile
This issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6. An app may be able to access information about a user's contacts.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 26.6 | 26.6 |
| apple | ipados | < 26.6 | 26.6 |
| apple | iphone_os | < 26.6 | 26.6 |
| apple | macos | < 26.6 | 26.6 |
| apple | macos | >= 26.0 < 26.6 | 26.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple iOS/iPadOS/macOS up to 26.5 access control
vuldb·2026-07-28
CVE-2026-43797 [LOW] Apple iOS/iPadOS/macOS up to 26.5 access control
A vulnerability labeled as problematic has been found in Apple iOS, iPadOS and macOS up to 26.5. This vulnerability affects unknown code. The manipulation results in improper access controls.
This vulnerability is cataloged as CVE-2026-43797. The attack must be initiated from a local position. There is no exploit available.
The affected component should be upgraded.
GHSA
This issue was addressed with improved checks.
ghsa_unreviewed·2026-07-27
CVE-2026-43797 [MEDIUM] CWE-200 This issue was addressed with improved checks.
This issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6. An app may be able to access information about a user's contacts.
No detection rules found.
No public exploits indexed.
2026-07-27
Published