Update Apple macOS for Root Remote Command Execution Vulnerability

This message is intended for U-M staff who are responsible for managing or are using macOS.

Summary

A root remote command execution vulnerability (CVE-2026-43760) was discovered in Apple macOS that allows apps to access user-sensitive data due to improper access restrictions. The issue is fixed in macOS Sonoma 14.8.8 and Tahoe 26.6.

Problem

Apple's advisory states that "an app may be able to access user-sensitive data," indicating a bypass of the access restrictions that normally isolate user data from arbitrary applications. The vulnerability is an improper access control issue in a macOS component.

Threats

An application running on an unpatched macOS host can bypass access restrictions and read user-sensitive data without user interaction or prior privileges.

Affected Versions

  • Apple macOS Sonoma prior to 14.8.8
  • Apple macOS Tahoe prior to 26.6
  • Systems running affected macOS builds with the vulnerable component enabled

Action Items

  • Install macOS Tahoe 26.6 or Sonoma 14.8.8 immediately.
  • Where an update cannot be installed immediately, disabling "VNC viewers may control screen with password" removes the vulnerable legacy authentication path.
  • If remote access is unnecessary, Screen Sharing and Remote Management should be disabled entirely.
  • Rotating the VNC password may address a suspected credential leak, but it does not repair the authorization flaw in an unpatched system.

The need for immediate action supersedes the remediation timeframes in Vulnerability Management (DS-21).

Technical Details

An attacker-controlled application, or a remote input that reaches the vulnerable component pre-authentication, invokes the exposed interface and retrieves user-sensitive data. Exploitation does not require elevated privileges or user interaction, which lowers the operational bar for use in follow-on attacks such as credential theft or reconnaissance.

Information for Users

MiWorkspace machines will be patched as soon as possible. If you have macOS Sonoma or Tahoe installed on your own devices that are not managed by the university, please update by installing macOS Tahoe 26.6 or Sonoma 14.8.8 immediately.

In general, the best protection for your devices is this: keep your software and apps up-to-date, do not click suspicious links in email, do not open shared documents or email attachments unless you are expecting them and trust the person who sent them, and only use secure, trusted networks. For more information, see Phishing & Scams, Secure Your Devices, and Secure Your Internet Connection on the U-M Safe Computing website.

Questions, Concerns, Reports

Please contact ITS Information Assurance through the ITS Service Center.