ZeroHour

CVE-2026-43690

mass

Race condition allows local kernel memory read in Apple macOS

CVSS
EPSS
Published
()
Modified
AI analysis

CVE-2026-43690 is a race condition in Apple's macOS caused by insufficient locking, which Apple addressed with improved locking mechanics. A local attacker with an existing account on an affected Mac could exploit the timing flaw to read portions of kernel memory, potentially exposing sensitive data such as pointers, credentials, or secrets that could aid in further privilege-escalation or sandbox-escape chains. Only users on unpatched macOS versions are affected; the fix ships in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. The issue requires local access, so remote exploitation is not in scope. No public proof of concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Patch affected Macs to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) as soon as practical via Software Update or your MDM deployment. Because exploitation requires local access, enforce least-privilege local account policies, limit who can run arbitrary code on shared or lab Macs, and review logs for suspicious local privilege-elevation attempts.

Affected
Apple macOS (Golden Gate)versions prior to macOS Golden Gate 27
Apple macOS Sequoiaversions prior to macOS Sequoia 15.8
Apple macOS Tahoeversions prior to macOS Tahoe 26.7
Estimated exposure
masslikely tens to hundreds of millions of Macs (unpatched macOS installs) — Apple's Mac installed base is estimated at well over 100 million active devices, and any device not yet updated to the three fixed releases is theoretically exposed to this local-only flaw.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A race condition was addressed with improved locking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A local user may be able to read kernel memory.

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

Apple's record patch cycle fixes 260+ CVEs across iOS 27 and macOS 27, including CUPS remote code execution, with no active exploitation reported.

Apple patched more than 260 CVEs across its operating systems and software, its largest single patch cycle ever, with iOS 27 fixing 122 flaws and macOS 27 Golden Gate fixing 204. Notable bugs include CVE-2026-43692, a CUPS validation issue allowing remote code execution, and CVE-2026-43689, an iOS privilege-escalation flaw granting root access. Ten CVEs were credited to AI-assisted bug hunting, including CVE-2026-65410 and CVE-2026-65409 found by Calif with Claude and Anthropic Research. None of the vulnerabilities are listed as actively exploited.