CVE-2026-43797
MEDIUM
5.5
CVSS 3.1
Description
This issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6. An app may be able to access information about a user's contacts.
Metadata
Severity & Metrics
5.5
MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
SSVC — CISA Coordinator
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Apple | iOS and iPadOS | — | 0 < 26.6 |
| Apple | macOS | — | 0 < 26.6 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | An app may be able to access information about a user's contacts |
| CWE-200 | adp | CWE-200 Exposure of Sensitive Information to an Unauthorized Actor |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 5.5 | MEDIUM | 3.1 | adp | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |