The building's janitor closet was labeled 'iCloud Repairs' but its key opened every door including the vault
CVE-2026-43783 is a local privilege escalation in Apple's DesktopServicesHelper daemon, a system service that Finder uses for privileged file operations. The daemon exposes a RepairPermissionsForCloudItems XPC handler intended to fix iCloud file ownership, but it performs no path validation — it will happily fchown any file or directory on disk to the calling user, recursively. An attacker sends a single XPC message targeting /private/etc/pam.d/, takes ownership, writes a permissive PAM rule (auth sufficient pam_permit.so into sudo_local), and runs sudo passwordless to become root. Affected versions: macOS Tahoe < 26.6 (all builds through 26.5.x). The exploit works from inside the macOS app sandbox, which substantially lowers the bar — even a sandboxed App Store app or a minimally-entitled binary can trigger it.
Apple scored this 7.8 HIGH with AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, and that is a fair call. The local access requirement is real friction — you need code running on the target first. However, there is a credible argument that Scope should be Changed (S:C) because the exploit breaks out of the macOS sandbox *and* elevates to root, which would bump the CVSS to 8.8. Apple chose the conservative reading. Seven independent researchers reported this bug, a polished PoC from Ilya Andr (andrd3v) of PT MAZE is on GitHub, and the exploit chain is trivially reproducible. Against that, EPSS sits at ~0.15% and there is no confirmed in-the-wild exploitation or KEV listing. The vendor severity is appropriate for the current threat landscape.
5 steps from start to impact.
Initial code execution on macOS
com.apple.security.app-sandbox and a mach-lookup.global-name temporary exception are needed. Delivery vectors include phishing with a signed .dmg, a trojanized developer tool, or a compromised App Store submission.- Target runs macOS Tahoe < 26.6
- Attacker achieves user-level code execution (any process)
- Gatekeeper and notarization block unsigned/unnotarized apps by default
- App Store review would likely catch overtly malicious XPC calls
- Enterprise MDM profiles can restrict app installation sources
XPC connection to DesktopServicesHelper
com.apple.DesktopServicesHelper. This daemon runs as root and handles Finder's privileged file operations. The connection is permitted from sandboxed processes because Finder itself is sandboxed and is the service's primary client. No special entitlement was required prior to the 26.6 fix.- Malicious process running on the target
- DesktopServicesHelper daemon is active (present on all macOS installs)
- Endpoint telemetry can detect unusual XPC connections to this service
- Blocking the daemon would break Finder — not a viable mitigation
Arbitrary chown via RepairPermissionsForCloudItems
RepairPermissionsForCloudItems XPC request with the path /private/etc/pam.d/ encoded via NSKeyedArchiver. The daemon does not validate that the supplied path resides within ~/Library/Mobile Documents/ or any iCloud container. It calls fchown recursively on the target directory, changing ownership to the calling user's UID. This is the core flaw: a missing authorization check on an overprivileged system service.- XPC connection established
- Target path exists and is owned by root
- No practical friction — the XPC request is a single dictionary with two keys
- The daemon performs no entitlement check on the caller (pre-26.6)
/private/etc/pam.d/ detects the ownership change. osquery scheduled queries on the file table for pam.d ownership changes work here.PAM configuration poisoning
/private/etc/pam.d/, the attacker writes a sudo_local file containing auth sufficient pam_permit.so. macOS's sudo PAM stack includes sudo_local if present, and pam_permit.so grants authentication unconditionally. This effectively disables password requirements for all sudo invocations.- User owns /private/etc/pam.d/
- pam_permit.so is available (ships with macOS)
- None — standard file write operation once ownership is gained
/private/etc/pam.d/. CrowdStrike Falcon and SentinelOne both flag PAM configuration changes on macOS.Root shell via passwordless sudo
sudo -s and receives an interactive root shell without any password prompt. Full system compromise is achieved: the attacker can install persistent implants, dump Keychain credentials, exfiltrate data, disable EDR agents, or pivot laterally using harvested SSH keys, CI/CD tokens, and signing certificates.- PAM sudo_local file in place with pam_permit.so
- None — sudo is a standard system binary
/var/log/authd) record the sudo event. Jamf Protect analytics detect passwordless sudo patterns.AllowIdentifiedDevelopers = false, restricting app launches to Mac App Store only. This eliminates the primary delivery vector for a malicious binary exploiting this CVE, since App Store review should catch overt XPC abuse patterns. Deploy within the noisgate mitigation SLA of 30 days for HIGH severity. This breaks Step 1 of the attack path — without code execution, the chain cannot start./private/etc/pam.d/. Specifically watch for creation of sudo_local. This is a detection control — the exploit still works, but your SOC will know within minutes. Deploy within 30 days per the noisgate mitigation SLA. This catches Steps 3–4 of the attack path, enabling rapid incident response.com.apple.private.desktopservices.cloud-repair-perm entitlement requirement to the XPC handler, blocking unauthorized callers entirely. This is the definitive remediation. Target completion within the noisgate remediation SLA of 180 days for HIGH severity — most fleets should already be on 26.6+ given the July GA date, making this primarily a sweep-up of stragglers.- macOS App Sandbox — the exploit specifically works from within the sandbox. DesktopServicesHelper's XPC service is accessible to sandboxed processes because Finder (its primary client) is sandboxed. Sandboxing provides zero mitigation.
- Network firewalls or segmentation — CVE-2026-43783 is a local privilege escalation with no network component. Firewall rules, VLANs, and micro-segmentation have no effect on the attack path.
- FileVault full-disk encryption — protects data at rest when the Mac is powered off. Provides no defense against a running process escalating privileges on an unlocked, booted system.
- Disabling iCloud Drive — the DesktopServicesHelper daemon runs regardless of iCloud Drive status. The
RepairPermissionsForCloudItemshandler is always registered and accessible; it does not check whether iCloud is actually configured.
The supporting signals.
| In-the-Wild Exploitation | No confirmed exploitation. Not listed on CISA KEV. No advisories from Mandiant, CrowdStrike, or Microsoft MSTIC reference active campaigns targeting this CVE. GreyNoise/Shodan data is N/A — this is a local-only vulnerability with no network scan surface. |
|---|---|
| Proof-of-Concept | Public and weaponized. Full PoC by Ilya Andr (andrd3v) of PT MAZE on GitHub: andrd3v/CVE-2026-43783. Cataloged in SecureWithUmer/CVE-2026-PoCs and Mr-xn/Penetration_Testing_POC. Detailed writeup published by PT SWARM via SecurityOnline. Trivially reproducible: single XPC call + two shell commands. |
| EPSS Score | 0.00153 (0.15%) — bottom quintile. 30-day exploitation probability is very low, consistent with a local-only vuln with no observed campaigns. |
| KEV Status | Not listed as of 2026-09-29. No indication of imminent addition. |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H = 7.8 HIGH. Local vector, low complexity, low privilege required, no user interaction. Scope:Unchanged is debatable — sandbox escape + root escalation arguably warrants S:C (which would yield 8.8). |
| Affected Versions | macOS Tahoe < 26.6 — all builds through 26.5.x confirmed. PoC validated on macOS 26.5.2. Older macOS releases (Sequoia, Sonoma) may contain the same daemon, but Apple has not issued advisories or patches for them. |
| Fixed Versions | macOS Tahoe 26.6 (GA July 27, 2026). Fix adds entitlement requirement com.apple.private.desktopservices.cloud-repair-perm to the XPC handler. Subsequent releases 26.6.1 (Aug 6) and 26.6.2 (Aug 17) also include the fix. |
| Scanning / Exposure | N/A for network scanning (Shodan, Censys, FOFA) — local privilege escalation, no remote attack surface. Vulnerability scanners: Tenable (plugin expected), Qualys (QID pending), Rapid7 InsightVM should detect via macOS version check. MDM compliance queries can identify unpatched hosts. |
| Disclosure Timeline | 2026-05-09: Reported to Apple. 2026-05-26: Fix in macOS 26.6 beta 1. 2026-07-27: macOS 26.6 GA release. 2026-08-11: CVE-2026-43783 assigned. 2026-09-14: Advisory entry added to Apple HT128067. |
| Credited Researchers | Seven independent reporters: Tommy DeVoss (Braze Security, @thedawgyg), Ilya Andr (andrd3v, PT MAZE), Mahmoud Abdelmoniem, Kujtim Kryeziu, YingQi Shi (@Mas0nShi, DBAppSecurity WeBin Lab), 이재영, Andreas Jaegersberger & Ro Achterberg (Nosebeard Labs), beist. The high independent-discovery count confirms low finding complexity. |
Sources.
- Apple Security Advisory — macOS Tahoe 26.6 (HT128067)
- andrd3v/CVE-2026-43783 — Full PoC on GitHub
- SecurityOnline — macOS DesktopServicesHelper LPE Writeup
- OpenCVE — CVE-2026-43783 Details
- CIS Advisory — Apple Privilege Escalation Vulnerabilities (2026-027)
- NVD — CVE-2026-43783
- SecureWithUmer/CVE-2026-PoCs — PoC Collection
Why this verdict
- Baseline is accurate: Apple's CVSS 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) correctly captures the local-only vector, low complexity, and complete CIA impact. The one debatable metric is Scope — a sandbox-escaping root escalation arguably warrants S:C (→ 8.8) — but the overall severity bucket stays HIGH either way.
- Public PoC pressures upward within band: A polished, single-file PoC is on GitHub. The exploit chain is three commands: connect XPC, chown pam.d, write sudo_local. Any red teamer or malware author can integrate this in hours. Seven independent researchers found it, confirming low discovery complexity. This is a slight upward pressure on urgency within the HIGH band but not enough to cross into CRITICAL.
- Local access requirement provides real friction: AV:L means the attacker needs code execution on the Mac first — phishing, trojanized app, or supply-chain delivery. macOS Gatekeeper + notarization + XProtect + App Store review create layered barriers to initial execution. This friction prevents upgrading to CRITICAL.
- EPSS and threat landscape confirm HIGH, not CRITICAL: EPSS 0.15% is bottom-quintile. No KEV listing, no in-the-wild exploitation, no threat actor campaigns. The vuln has been patchable since July 2026 (~3 months) and no exploitation has materialized. This supports HIGH-priority patching, not emergency response.
- Role multiplier: macOS is a general-purpose workstation OS. (a) *Low-value role* — personal/lab Macs: host-level impact only. (b) *Typical role* — corporate knowledge-worker Macs: host compromise + credential theft from Keychain. (c) *High-value role* — developer workstations with code-signing certificates, CI/CD tokens (GitHub PATs, GitLab tokens), SSH keys to production, and Xcode signing infrastructure: root → Keychain dump → signing cert theft → supply-chain-scale blast radius. Developer Macs represent ~15-25% of enterprise macOS fleets. This ≥1% high-value-role share sets a HIGH floor. The verdict already sits at HIGH, confirming rather than overriding.
- Sandbox bypass is notable but does not change the bucket: The exploit working from inside the macOS sandbox lowers post-initial-access friction — even App Store apps or properly sandboxed binaries are potential vectors. This is more concerning than a typical LPE, but the initial code execution requirement and Apple's App Store review process add compensating friction that caps the severity below CRITICAL.
Why not higher?
CRITICAL would require either a remote attack vector or the affected component being canonically high-value-role infrastructure (hypervisor, IdP, domain controller, network edge appliance, CA). macOS is a workstation OS. The local access prerequisite means the attacker already has an initial foothold — every macOS endpoint has multiple layers (Gatekeeper, notarization, XProtect, EDR) that must first be bypassed. The worst-case developer-workstation supply-chain scenario is real but requires additional steps beyond root (Keychain unlock, certificate export, injection into build pipeline), adding friction to the catastrophic chain.
Why not lower?
Downgrading to MEDIUM would ignore three compounding factors: (1) the exploit is trivially reliable — no race window to win, no heap grooming, just one XPC message; (2) it works from the sandbox, making every running app a potential attack surface rather than just unsigned binaries; (3) root on a developer Mac is one Keychain dump away from supply-chain compromise, and developer Macs represent ≥15% of enterprise macOS fleets. The HIGH floor set by this high-value-role analysis holds firmly.
Crowdsourced verification payload.
Run on each target macOS host as any user — no elevated privileges required. Invoke with bash cve-2026-43783-check.sh. The script checks macOS product version against the known-fixed release (26.6) and prints VULNERABLE, PATCHED, or UNKNOWN.
#!/bin/bash
# CVE-2026-43783 Verification — macOS DesktopServicesHelper LPE
# Run on the target macOS host. No privileges required.
# Exit codes: 0=PATCHED 1=VULNERABLE 2=UNKNOWN
set -euo pipefail
OS_NAME=$(sw_vers -productName 2>/dev/null || true)
OS_VERSION=$(sw_vers -productVersion 2>/dev/null || true)
if [ -z "$OS_VERSION" ]; then
echo "UNKNOWN — unable to determine OS version. Is this macOS?"
exit 2
fi
if [ "$OS_NAME" != "macOS" ]; then
echo "UNKNOWN — not macOS (detected: $OS_NAME). CVE-2026-43783 is macOS-only."
exit 2
fi
MAJOR=$(echo "$OS_VERSION" | cut -d. -f1)
MINOR=$(echo "$OS_VERSION" | cut -d. -f2)
if [ "$MAJOR" -gt 26 ]; then
echo "PATCHED — macOS $OS_VERSION is newer than the affected Tahoe 26.x line."
exit 0
elif [ "$MAJOR" -lt 26 ]; then
# Apple has not confirmed older releases are affected
echo "UNKNOWN — macOS $OS_VERSION predates macOS Tahoe 26. Apple has not"
echo " issued an advisory for older releases. Investigate independently."
exit 2
fi
# macOS Tahoe 26.x — check minor version
if [ "$MINOR" -ge 6 ]; then
echo "PATCHED — macOS Tahoe $OS_VERSION includes the fix for CVE-2026-43783 (fixed in 26.6)."
exit 0
else
echo "VULNERABLE — macOS Tahoe $OS_VERSION is affected by CVE-2026-43783."
echo " Component: DesktopServicesHelper (com.apple.DesktopServicesHelper)"
echo " Impact: Local privilege escalation to root via XPC"
echo " Mechanism: RepairPermissionsForCloudItems arbitrary chown -> PAM poisoning -> sudo root"
echo " Fix: Update to macOS Tahoe 26.6 or later"
exit 1
fi