ZeroHour

CVE-2026-43696

mass

Authorization Bypass in macOS Lets Apps Capture Touch Bar Content

CVSS
EPSS
Published
()
Modified
AI analysis

An authorization flaw in macOS, caused by insufficient entitlement checks, allows a locally installed app to capture Touch Bar content without the user's permission. A malicious or compromised app on an affected Mac could passively read whatever is displayed on the Touch Bar — which can include predictive-text suggestions and app-specific input — making this a keystroke-adjacent privacy leak rather than a remote attack. The issue is fixed in macOS Golden Gate 27 and affects Macs with Touch Bar hardware (2016–2019 MacBook Pro models) running earlier macOS versions. Exploitation requires the attacker to already run an app on the target Mac, so the practical risk is local snooping by untrusted software. No CVSS score has been assigned yet, there is no public proof of concept, no CISA KEV entry, and no known exploitation; the fix shipped in Apple's broad September update wave.

What to do: Upgrade all Touch Bar–equipped Macs to macOS Golden Gate 27 or later, and confirm which older units are eligible for the update, since Touch Bar hardware that cannot upgrade may remain exposed. Because exploitation requires a local app, audit installed software and screen-capture/TCC permission grants on these machines. Treat unpatched Touch Bar Macs as carrying a typed-input privacy risk and avoid running untrusted apps on them.

Affected
Apple macOSAll versions prior to macOS Golden Gate 27 (the advisory does not specify a lower bound for the affected range); exposure requires Touch Bar hardware (2016–2019
Estimated exposure
masstens of millions of Touch Bar–equipped Macs plausibly still in use (subset of Apple's 100M+ active Mac installed base) — The Touch Bar shipped on MacBook Pro models sold from 2016 through 2019, a period in which Apple sold tens of millions of such units, many of which remain in service — this estimates the hardware-capable population, not confirmed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authorization issue was addressed with improved entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to capture Touch Bar content without authorization.

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.