Apple Permissions Flaw Lets Malicious Apps Gain Root on iOS, iPadOS, macOS, visionOS
AI analysis
CVE-2026-43689 is a permissions issue in Apple's operating systems where insufficient restrictions allowed a malicious application to elevate itself to root privileges, effectively breaking out of the app sandbox. Exploitation is local: an attacker must first get a malicious app onto the victim's iPhone, iPad, Mac, or Vision Pro, after which the flaw grants the app full root control of the device. Root access on these platforms exposes sensitive user data and enables deep persistence on the compromised device. Apple addressed the issue with additional restrictions in iOS 26.7/iPadOS 26.7, iOS 27/iPadOS 27, macOS Golden Gate 27, and visionOS 27, released as part of Apple's September 'Updates Everything' wave. No public proof of concept is known, the flaw is not on the CISA KEV list, and there are no reports of in-the-wild exploitation.
What to do: Patch promptly: update iPhones and iPads to iOS/iPadOS 26.7 or later (or iOS/iPadOS 27), Macs to macOS Golden Gate 27, and Vision Pro headsets to visionOS 27 as soon as the rollout reaches the device. Because exploitation requires a malicious app to already be installed, audit installed apps and remove anything sideloaded, enterprise-signed, or from untrusted sources, and keep installations limited to the App Store. MDM administrators should push these updates fleet-wide and review device logs for unexpected privilege-escalation or sandbox-escape behavior.
Affected
| Apple iOS | versions prior to iOS 26.7 on the 26.x line (fixed in iOS 26.7; iOS 27 and later not affected) |
| Apple iPadOS | versions prior to iPadOS 26.7 on the 26.x line (fixed in iPadOS 26.7; iPadOS 27 and later not affected) |
| Apple macOS Golden Gate | versions prior to macOS Golden Gate 27 (fixed in macOS Golden Gate 27) |
| Apple visionOS | versions prior to visionOS 27 (fixed in visionOS 27) |
Estimated exposure
mass≈1 billion+ devices (Apple's global active install base across iPhone, iPad, Mac, and Vision Pro) — Apple has publicly reported well over one billion active iPhones and roughly two billion active devices worldwide, and the flaw spans every iPhone, iPad, Mac, and Vision Pro not yet updated to the patched versions, so essentially the…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. A malicious app may be able to gain root privileges.