CVE-2026-43783High· 7.8▾ MidnightPoC availableA race condition was addressed with improved locking. This issue is fixed in macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 42.9 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
— → 7.8
none → high
Last analysed / modified upstream
0.1%
1 GitHub repo
0.1% → 0.2%
A race condition was addressed with improved locking. This issue is fixed in macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
macos < 26.6Upgrade past the affected range:
macos 26.6Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84562Medium· 4.7A race condition was addressed with additional validation
CVE-2026-64705Medium· 5.5A buffer overflow was addressed with improved bounds checking
CVE-2026-43760High· 8.6An access issue was addressed with improved access restrictions
CVE-2026-43763Medium· 5.5A permissions issue was addressed by removing the vulnerable code
CVE-2026-84550Medium· 4.7A race condition was addressed with additional validation
CVE-2026-43748Critical· 9.8An out-of-bounds write issue was addressed with improved bounds checking