High severity7.1NVD Advisory· Published Jul 27, 2026· Updated Jul 29, 2026
CVE-2026-43672
CVE-2026-43672
Description
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious application may be able to bypass Privacy preferences.
Affected products
4- Range: = 15.7.8
- Range: = 14.8.8
- Range: = 26.6
Patches
Vulnerability mechanics
References
3- support.apple.com/en-us/128067nvdVendor AdvisoryRelease Notes
- support.apple.com/en-us/128071nvdVendor AdvisoryRelease Notes
- support.apple.com/en-us/128072nvdVendor AdvisoryRelease Notes
News mentions
4- Apple Patches Everything (July 2026), (Wed, Jul 29th)SANS Internet Storm Center · Jul 29, 2026
- Apple Releases 25 macOS Security Patches, Including CUPS Privilege Escalation FlawVypr Intelligence · Jul 27, 2026
- Apple Patches 25 macOS Vulnerabilities in Single July 2026 DisclosureVypr Intelligence · Jul 27, 2026
- macOS Tahoe: 25 Security Flaws Patched in Single July 2026 DisclosureVypr Intelligence · Jul 27, 2026