CVE-2026-43728

Apple · macOS

A state management vulnerability in the Apple macOS Keychain allows an attacker to modify sensitive state information.

Executive summary

A state management flaw in Apple macOS allows unauthorized modification of the Keychain, potentially compromising stored secrets and system trust.

Vulnerability

This is a state management vulnerability where the Keychain does not correctly track or enforce its own internal state. An unauthenticated remote attacker can exploit this to modify the Keychain state, which can lead to further security bypasses.

Business impact

With a CVSS score of 7.5, this high-severity vulnerability poses a significant risk to the security of credentials and secrets stored within the macOS Keychain. Modification of the Keychain state can enable attackers to bypass authentication mechanisms, compromise trust decisions, or gain unauthorized access to sensitive application data.

Remediation

Immediate Action: Update Apple macOS Tahoe to version 26.6 immediately to address the state management flaw.

Proactive Monitoring: Monitor system logs for unusual modifications to Keychain-related configuration or unexpected behavior in applications that rely on Keychain-stored secrets.

Compensating Controls: Enforce strict access controls and ensure that sensitive credentials are not stored in ways that rely exclusively on default Keychain state assumptions.

Exploitation status

Public Exploit Available: False

Analyst recommendation

The ability to modify the state of the Keychain represents a significant security breakdown in the macOS environment. Security teams must prioritize updating to macOS Tahoe 26.6 to ensure that Keychain integrity is restored and protected against unauthorized modification.