Improper access control in macOS - CVE-2026-43700
Published: July 8, 2026
Vulnerability identifier: #VU137087
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-43700
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper access control in WebKit when rendering content. A local user can trigger processing of crafted content to disclose sensitive information.
Affected software
macOS
visionOS
tvOS
Apple iOS
iPadOS
watchOS
Apple Safari
visionOS
tvOS
Apple iOS
iPadOS
watchOS
Apple Safari
How to mitigate CVE-2026-43700
Install update from vendor's website.
macOS - update to 26.5.2 25F84
visionOS - update to 26.6
tvOS - update to 26.6 23L773
Apple iOS - addressed in versions 18.7.10 22H374, 26.5.2 23F84
iPadOS - addressed in versions 18.7.10 22H374, 26.5.2 23F84
Apple Safari - update to 26.5.2
watchOS - update to 26.6 23U67
visionOS - update to 26.6
tvOS - update to 26.6 23L773
Apple iOS - addressed in versions 18.7.10 22H374, 26.5.2 23F84
iPadOS - addressed in versions 18.7.10 22H374, 26.5.2 23F84
Apple Safari - update to 26.5.2
watchOS - update to 26.6 23U67
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple macOS Tahoe
- Multiple vulnerabilities in Apple visionOS
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in iOS 26 and iPadOS 26
- Multiple vulnerabilities in Apple Safari
- Multiple vulnerabilities in iOS 18 and iPadOS 18