Skip to content
AppleCVE-2026-43657

Apple iOS and iPadOS: improper privilege management

Low3.3CVE-2026-43657 · Published Aug 25, 2026 · updated Aug 31, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5. A malicious app may be able to enumerate installed apps.

Apple advisory

Affected versions

PackageAffectedFixed in
iOS and iPadOS
Product
< 26.526.5
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
CISA (its enrichment of the CVE record)
Weakness
CWE-269

More Apple advisories

All Apple
Advisory
## Impact An attacker who can choose a container or exec id may be able to...
HighAug 30
Apple iOS and iPadOS: buffer overflow
Medium5.5Aug 25
Apple iOS and iPadOS: null pointer dereference
Medium5.5Aug 25
Apple Safari: protection mechanism failure
High8.8Aug 25
Apple watchOS: improper access control
Low2.4Aug 21
Apple macOS: out-of-bounds read
Medium4.3Aug 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.