Access Control Vulnerability in Safari and Apple Products
CVE-2026-43821

6.5MEDIUM

Key Information:

Vendor

Apple

Vendor
CVE Published:
27 July 2026

What is CVE-2026-43821?

A significant access control issue was identified in Safari and several Apple operating systems, allowing apps to potentially access and read files outside their designated sandbox environments. This flaw highlights the importance of stringent access restrictions to protect user data. Apple has addressed this vulnerability with enhanced access controls in the latest versions of Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS. Users are encouraged to update their devices to ensure they are protected against this issue.

Affected Version(s)

iOS and iPadOS 0 < 26.6

macOS 0 < 26.6

Safari 0 < 26.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.