CVE-2026-43792
MEDIUM
6.5
CVSS 3.1
Description
An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.
Metadata
Severity & Metrics
6.5
MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
SSVC — CISA Coordinator
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Apple | macOS | — | 0 < 26.6 |
| Apple | Safari | — | 0 < 26.6 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | An app may be able to access sensitive user data |
| CWE-285 | adp | CWE-285 Improper Authorization |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 6.5 | MEDIUM | 3.1 | adp | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |