CVE-2026-43783
massRace Condition in macOS Tahoe Allows Malicious Apps to Gain Root
A race condition (CWE-362) in macOS was addressed with improved locking in macOS Tahoe 26.6; a malicious app already running on an affected Mac may be able to elevate its privileges to root. Exploitation is local and low-complexity (AV:L/AC:L/PR:L/UI:N): the attacker first needs a victim to install and launch their app, then abuses a timing window in a privileged code path to gain full system control with high impact on confidentiality, integrity, and availability. Any Mac running a macOS version prior to the Tahoe 26.6 update is potentially affected, so the practical risk is malicious or trojanized applications combining initial foothold with privilege escalation. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild is known. Local privilege escalation bugs of this type are frequently chained in real-world campaigns once details or exploits surface, so timely patching is recommended.
What to do: Upgrade all Macs to macOS Tahoe 26.6 or later as soon as possible via Software Update. Since exploitation requires a malicious app to run locally, enforce Gatekeeper/notarization and restrict installs to the App Store or trusted, identified developers in the interim. Review endpoint logs for user-launched apps spawning or injecting into root-owned processes.
| Apple macOS (Tahoe) | Versions prior to macOS Tahoe 26.6 (issue fixed in macOS Tahoe 26.6) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A race condition was addressed with improved locking. This issue is fixed in macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
- Vendors
- apple
- Products
- macos
- Weakness
- CWE-362
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.