ZeroHour

CVE-2026-43689

mass

Apple Permissions Flaw Lets Malicious Apps Gain Root on iOS, iPadOS, macOS, visionOS

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-43689 is a permissions issue in Apple's operating systems where insufficient restrictions allowed a malicious application to elevate itself to root privileges, effectively breaking out of the app sandbox. Exploitation is local: an attacker must first get a malicious app onto the victim's iPhone, iPad, Mac, or Vision Pro, after which the flaw grants the app full root control of the device. Root access on these platforms exposes sensitive user data and enables deep persistence on the compromised device. Apple addressed the issue with additional restrictions in iOS 26.7/iPadOS 26.7, iOS 27/iPadOS 27, macOS Golden Gate 27, and visionOS 27, released as part of Apple's September 'Updates Everything' wave. No public proof of concept is known, the flaw is not on the CISA KEV list, and there are no reports of in-the-wild exploitation.

What to do: Patch promptly: update iPhones and iPads to iOS/iPadOS 26.7 or later (or iOS/iPadOS 27), Macs to macOS Golden Gate 27, and Vision Pro headsets to visionOS 27 as soon as the rollout reaches the device. Because exploitation requires a malicious app to already be installed, audit installed apps and remove anything sideloaded, enterprise-signed, or from untrusted sources, and keep installations limited to the App Store. MDM administrators should push these updates fleet-wide and review device logs for unexpected privilege-escalation or sandbox-escape behavior.

Affected
Apple iOSversions prior to iOS 26.7 on the 26.x line (fixed in iOS 26.7; iOS 27 and later not affected)
Apple iPadOSversions prior to iPadOS 26.7 on the 26.x line (fixed in iPadOS 26.7; iPadOS 27 and later not affected)
Apple macOS Golden Gateversions prior to macOS Golden Gate 27 (fixed in macOS Golden Gate 27)
Apple visionOSversions prior to visionOS 27 (fixed in visionOS 27)
Estimated exposure
mass≈1 billion+ devices (Apple's global active install base across iPhone, iPad, Mac, and Vision Pro) — Apple has publicly reported well over one billion active iPhones and roughly two billion active devices worldwide, and the flaw spans every iPhone, iPad, Mac, and Vision Pro not yet updated to the patched versions, so essentially the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. A malicious app may be able to gain root privileges.

Vendors
apple
Products
ipados, iphone os, macos, visionos
Weakness
CWE-862
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

Apple's record patch cycle fixes 260+ CVEs across iOS 27 and macOS 27, including CUPS remote code execution, with no active exploitation reported.

Apple patched more than 260 CVEs across its operating systems and software, its largest single patch cycle ever, with iOS 27 fixing 122 flaws and macOS 27 Golden Gate fixing 204. Notable bugs include CVE-2026-43692, a CUPS validation issue allowing remote code execution, and CVE-2026-43689, an iOS privilege-escalation flaw granting root access. Ten CVEs were credited to AI-assisted bug hunting, including CVE-2026-65410 and CVE-2026-65409 found by Calif with Claude and Anthropic Research. None of the vulnerabilities are listed as actively exploited.