PT-2026-91498 · Apple · Apple Macos
CVE-2026-43783
·
Published
2026-07-27
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
macOS versions prior to Tahoe 26.6
Description
A race condition exists where a malicious application can gain root privileges. This is achieved through a single XPC request to the
DesktopServicesHelper component, allowing an attacker to perform an arbitrary chown (change ownership) of any path on the disk. A race condition is a situation where the system's behavior depends on the sequence or timing of uncontrollable events.Recommendations
Update to macOS Tahoe 26.6.
Fix
DoS
LPE
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos