Back to overview

CVE-2026-43728

HIGH
7.5
CVSS 3.1
Description
This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26.6. An attacker may be able to modify the state of the Keychain.

Metadata

CVE ID
CVE-2026-43728
State
PUBLISHED
Assigner
apple
Reserved
2026-05-01 22:46 UTC
Published
2026-07-27 20:13 UTC
Last updated
2026-07-28 19:06 UTC
Primary CWE
CWE-362
CWE-362 Concurrent Execution using Shared Resource with Impr…
Vendor / Product
Apple / macOS
Sources
cve.org  ·  NVD

Severity & Metrics

7.5 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Apple macOS 0 < 26.6
Weakness (CWE)
CWESourceDescription
cna An attacker may be able to modify the state of the Keychain
CWE-362 adp CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.5 HIGH 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Back to overview