Race Condition Vulnerability in Apple macOS
CVE-2026-43690

4.7MEDIUM

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-43690?

A race condition in macOS has been identified that allows local users to potentially access kernel memory. This vulnerability could be exploited through inadequate locking mechanisms that fail under specific timing circumstances. Apple has announced fixes in versions 27 of Golden Gate, 15.8 of Sequoia, and 26.7 of Tahoe, which aim to address this issue and enhance system security.

Affected Version(s)

macOS 0 < 15.8

macOS 0 < 26.7

macOS 0 < 27

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.