ZeroHour

CVE-2026-43786

mass

Local Privilege Escalation to Root via Missing Entitlement Checks in macOS

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-43786 is a local privilege escalation vulnerability in macOS caused by improper handling of privileges (CWE-280), where insufficient entitlement checks allow a locally running app to gain root privileges. It is triggered by an app already executing on the target Mac with ordinary user-level privileges, requiring no user interaction, after which the attacker obtains full root access to read, modify, or delete anything on the system and establish persistent, security-tool-bypassing control. Affected systems are Macs running macOS Sequoia before 15.8 and macOS Tahoe before 26.7; Apple addressed the issue with additional entitlement checks and shipped fixes in macOS Sequoia 15.8, macOS Tahoe 26.7, and macOS Golden Gate 27. Because the attack vector is local (AV:L, PR:L), this flaw is primarily a post-compromise escalation step for malware or a hostile app rather than a remote entry point. No public proof of concept is known and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation status is none known.

What to do: Update affected Macs to macOS Sequoia 15.8, macOS Tahoe 26.7, or Golden Gate 27 (or later) via System Settings > General > Software Update, prioritizing machines where users install third-party or untrusted apps. Because exploitation requires local code execution, enforce Gatekeeper/notarization and restrict app installation to trusted sources, and monitor for unexpected processes gaining root or spawning with elevated entitlements. Treat this as a chain link: pair the patch with endpoint detection so malware that achieves initial execution cannot escalate to root.

Affected
Apple macOS Sequoiaversions before 15.8 (fixed in 15.8)
Apple macOS Tahoeversions before 26.7 (fixed in 26.7)
Estimated exposure
masstens of millions of Macs potentially exposed pending updates — Apple's active Mac installed base exceeds 100 million devices and macOS Sequoia and Tahoe are the two most recently supported major versions, so a large fraction of that base plausibly runs vulnerable builds before the 15.8/26.7 patches…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

Vendors
apple
Products
macos
Weakness
CWE-280
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.