macOS Authorization flaw allows PH attacker to view data (before 15.7.8/14.8.8)
CVE-2026-43766 Published on July 27, 2026
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker with physical access to a locked device may be able to view sensitive user information.
Vulnerability Analysis
CVE-2026-43766 is exploitable with physical access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is an authentification Vulnerability?
When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
CVE-2026-43766 has been classified to as an authentification vulnerability or weakness.
Products Associated with CVE-2026-43766
stack.watch emails you whenever new vulnerabilities are published in Apple macOS or Apple Macos Sonoma. Just hit a watch button to start following.
Affected Versions
Apple macOS:- Before 14.8.8 is affected.
- Before 15.7.8 is affected.
- Before 26.6 is affected.