TL;DR
This month, Apple issued critical security patches to address a local privilege escalation flaw in macOS. The macOS CoreServices vulnerability allows a malicious application to gain root privileges. Developers have released a public proof-of-concept exploit.
- CVE: CVE-2026-43786
- CVSS: 7.8 (High · CVSSv3)
- Product: Apple macOS
- Affected: < 15.8, < 26.7, < 27
- Impact: This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden...
- Status: No confirmed exploitation yet
- Patched in: 15.8, 26.7, 27
- EPSS: 0.2% (30-day)
- Action: Update to 15.8, 26.7, 27 now
Turn Apple CVEs into GitHub Issues automatically — no copy-pasting, no duplicates.
Try Team free for 14 daysWhy It Matters
Millions of Apple computers rely on CoreServices to manage background system operations. A macOS CoreServices vulnerability poses severe risks to user data. Attackers can hijack this component to gain complete control over a machine. Researchers published a functional proof-of-concept exploit for CVE-2026-43786 on GitHub. This public disclosure drastically lowers the barrier to entry for other attackers.
Just dropped a PoC for CVE-2026-43786. Local privilege escalation to root through macOS CoreServices.
Patched in Sequoia 15.8, Tahoe 26.7 and Golden Gate 27.https://t.co/0frVo0LdbZ@malwation pic.twitter.com/R26viUJ5oK
— Kağan IŞILDAK (@kaganisildak) September 21, 2026
How The Attack Works
The flaw exists within the entitlement verification process of macOS CoreServices. An attacker must first execute a malicious application on the target system. This application sends specially crafted requests to the vulnerable background service. The service fails to validate the application’s security entitlements properly. Consequently, the application bypasses system restrictions and executes commands with root privileges. Security researcher Kujtim Kryeziu from Sentry originally discovered and reported this Apple privilege escalation vector.
Affected Versions
This privilege escalation flaw impacts multiple generations of the Mac operating system. Vulnerable versions include releases prior to macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Patch Or Mitigation Steps
System administrators and users must install the official Apple security updates immediately. Apple addressed the issue by adding strict entitlement checks to the vulnerable service. Users running older systems should update to macOS Tahoe 26.7 or macOS Sequoia 15.8. Users on the newest platform must apply the macOS Golden Gate 27 update. Updating quickly prevents attackers from utilizing the public exploit code against your devices.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!