Description
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A maliciously crafted app may be able to bypass code signing enforcement.
Published: 2026-07-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A validation flaw in Apple operating systems allows a maliciously crafted application to bypass the platform's code signing enforcement. The vulnerability stems from insufficient input sanitization, enabling an attacker to install and run code that would otherwise be rejected by the system. Based on the description, it is inferred that an attacker could execute arbitrary code with the privileges of the compromised application, potentially compromising device integrity and confidentiality.

Affected Systems

The issue affects Apple devices running iOS, iPadOS, macOS, tvOS, visionOS, and watchOS versions prior to 26.6. The flaw has been addressed in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating that no mass exploitation has been observed. With a CVSS score of 7.1, the issue is deemed moderate to high severity, reflecting the potential for significant privilege escalation. Based on the information provided, no public exploits are known; this is an inference drawn from the absence of reported exploitation. The risk remains theoretical until the operating system is updated, but the potential for serious compromise warrants urgent remediation.

Generated by OpenCVE AI on August 4, 2026 at 23:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest software update that includes iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, or watchOS 26.6
  • Enable automatic OS updates to ensure devices receive security patches as soon as they become available
  • Configure mobile device management (MDM) policies to enforce strictly signed App Store or approved enterprise distribution methods, preventing installation of unsigned or malformed applications

Generated by OpenCVE AI on August 4, 2026 at 23:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Input Validation Exploit Allows Bypassing of Code Signing Enforcement on Apple OSes

Tue, 04 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title App bypasses code signing enforcement via input validation flaw
Weaknesses CWE-287

Thu, 30 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title App bypasses code signing enforcement via input validation flaw
Weaknesses CWE-287

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A maliciously crafted app may be able to bypass code signing enforcement.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:25:47.377Z

Reserved: 2026-05-01T22:46:27.821Z

Link: CVE-2026-43813

cve-icon Vulnrichment

Updated: 2026-07-28T14:25:20.308Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:04.430

Modified: 2026-07-28T20:04:46.760

Link: CVE-2026-43813

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T00:00:03Z

Weaknesses
  • CWE-20

    Improper Input Validation