Threat Advisory

macOS CoreServices Flaw Enables Core Rights to Manipulated Software

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A local privilege escalation flaw identified as CVE-2026-43786 with a CVSS score of 7.8 exists within the entitlement verification process of macOS CoreServices, allowing a malicious application to gain root privileges by bypassing system restrictions and executing commands with elevated access. The vulnerability affects macOS CoreServices and poses risks to user data by enabling unauthorized applications to abuse background system operations and potentially gain complete control over a machine. The flaw can be exploited when an attacker executes a malicious application on the target system and sends specially crafted requests to the vulnerable background service, which fails to properly validate the application's security entitlements.

RECOMMENDATIONS:

  • We recommend you to update macOS CoreServices to below version:
  • macOS Sequoia to version 15.8 or later.
  • macOS Tahoe to version 26.7 or later.
  • macOS Golden Gate to version 27 or later.

REFERENCES:

The following reports contain further technical details:[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A local privilege escalation flaw identified as CVE-2026-43786 with a CVSS score of 7.8 exists within the entitlement verification process of macOS CoreServices, allowing a malicious application to gain root privileges by bypassing system restrictions and executing commands with elevated access. The vulnerability affects macOS CoreServices and poses risks to user data by enabling unauthorized applications to abuse background system operations and potentially gain complete control over a machine. The flaw can be exploited when an attacker executes a malicious application on the target system and sends specially crafted requests to the vulnerable background service, which fails to properly validate the application's security entitlements.

RECOMMENDATIONS:

  • We recommend you to update macOS CoreServices to below version:
  • macOS Sequoia to version 15.8 or later.
  • macOS Tahoe to version 26.7 or later.
  • macOS Golden Gate to version 27 or later.

REFERENCES:

The following reports contain further technical details:[emaillocker id="1283"]

[/emaillocker]
crossmenu