APPLE has addressed a significant vulnerability tracked as CVE-2026-43723, which allowed a local application to gain root privileges through the mediaremoted service. This flaw has a CVSS score of 7.8 and affects multiple versions of iOS, iPadOS, tvOS, visionOS, watchOS, and macOS prior to the updates including iOS 26.6 and macOS 15.7.8. The exploitation involves a path handling issue that permits unauthorized file access.
While public proof-of-concept exploit code exists, no confirmed real-world exploitation has been reported yet. Timely updates to the patched versions are urged for users to mitigate the risks.