Race Condition Vulnerability in Apple iOS, iPadOS, and macOS Products
CVE-2026-43659

4.7MEDIUM

Key Information:

Vendor

Apple

Vendor
CVE Published:
11 May 2026

What is CVE-2026-43659?

A race condition has been identified in various Apple operating systems that could allow unauthorized access to sensitive user data. This issue arises from insufficient validation processes, which have been addressed in the latest updates. Users are encouraged to install the latest versions of iOS, iPadOS, and macOS to mitigate potential risks. Failure to update may leave systems exposed to exploit attempts that leverage this vulnerability.

Affected Version(s)

iOS and iPadOS 0 < 18.7.9

iOS and iPadOS 0 < 26.5

macOS 0 < 14.8.7

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.