securityonline.info 8/13/2026, 4:11:47 PM · external

Apple patches root privilege flaw in mediaremoted on iOS, macOS

Apple patches root privilege flaw in mediaremoted on iOS, macOS
CyberSIXT Evidence Panel
Primary Source support.apple.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

APPLE has addressed a significant vulnerability tracked as CVE-2026-43723, which allowed a local application to gain root privileges through the mediaremoted service. This flaw has a CVSS score of 7.8 and affects multiple versions of iOS, iPadOS, tvOS, visionOS, watchOS, and macOS prior to the updates including iOS 26.6 and macOS 15.7.8. The exploitation involves a path handling issue that permits unauthorized file access.

While public proof-of-concept exploit code exists, no confirmed real-world exploitation has been reported yet. Timely updates to the patched versions are urged for users to mitigate the risks.

View Primary Source Via securityonline.info

Article by CyberSIXT