ZeroHour

CVE-2026-43691

mass

macOS Path Validation Flaw Could Let Apps Escalate to Root

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-43691 is a path handling vulnerability in macOS in which insufficient validation of file paths allows a locally running app to elevate its privileges to root. Exploitation requires an attacker to first get a malicious or compromised app onto a victim's Mac, after which the app can abuse the flawed path handling to gain full system privileges. The issue was addressed with improved validation and is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, meaning Macs running earlier builds of these releases remain exposed. As a local privilege escalation, it is primarily a post-compromise primitive that malware or a limited user could use to take over the machine, rather than a remote entry vector. There is no public proof of concept, the CVE is not in CISA's KEV catalog, and no exploitation in the wild has been reported.

What to do: Patch to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) and push the updates via MDM as soon as they clear testing. Because exploitation requires a malicious app already on the endpoint, enforce Gatekeeper/notarization policies and block unsigned or untrusted software to shrink the attack surface. Monitor EDR telemetry for existing processes attempting unexpected privilege escalation to root.

Affected
Apple macOS Sequoiabefore 15.8
Apple macOS Tahoebefore 26.7
Apple macOS Golden Gatebefore 27
Estimated exposure
masson the order of 100M+ active Macs potentially exposed before patching — Apple's installed base exceeds 1 billion active devices and macOS accounts for roughly 15% of desktop OS market share, implying a global active Mac base well over 100 million, most of which would be unpatched until updates are applied.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

Vendors
apple
Products
macos
Weakness
CWE-22
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.