CVE-2026-43786 is an entitlement-validation vulnerability in macOS. Insufficient entitlement checks allow an application to gain root privileges. Apple corrected the issue by adding entitlement checks in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains one substantial standalone C proof-of-concept/exploit and a README. The C program targets the macOS com.apple.ManagedClient.agent Mach service, asserting that its privileged LDAP bind operation lacks sender or entitlement verification. It uses Mach/MIG interfaces to issue a bind request (0x4668) for localhost, while hosting its own LDAP service on TCP/389. The embedded LDAP implementation builds and serves a malicious directory tree containing the hard-coded pocroot account (UID 4444) and an asserted administrative membership. After flushing name-service caches and confirming that getpwnam resolves the rogue account, it attempts su followed by sudo to acquire a root shell. A cleanup path sends unbind request 0x4669 and stops the local listener. The README describes CVE-2026-43786 as an Apple macOS improper-entitlement-validation local privilege escalation. The source is operational rather than a detection-only script, although its stated vulnerability applicability and affected-version claims would require independent validation.
The repository contains one standalone C source file, CVE-2026-43786.c (35,493 bytes), with no exploit-framework dependencies. It is an operational local macOS privilege-escalation exploit targeting the Apple ManagedClient agent's Mach IPC interface. The code includes BER/LDAP encoding and parsing utilities, an in-memory directory information tree, a threaded rogue LDAP server, Mach/MIG setup and message dispatch, cache flushing, account-resolution checks, and cleanup logic. The exploit runs as a normal user, launches an LDAP listener on port 389, and invokes ManagedClient verb 0x4668 to bind the service to a payload specifying localhost. Its claimed flaw is that this privileged bind operation has no sender verification. The rogue LDAP directory supplies the hard-coded pocroot user with UID 4444, password pocpass123, and GID 80/admin membership. After confirming getpwnam() resolves that account, it attempts su followed by sudo to reach a root shell. It retries the bind operation up to five times and cleans up by issuing verb 0x4669 and stopping the listener. No external command-and-control or remote attacker infrastructure is embedded; the relevant network service is entirely local, although it listens on all interfaces.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS privilege-escalation vulnerability caused by insufficient entitlement checks, allowing an application to potentially obtain root privileges.
macOS Tahoe web-content null-pointer denial-of-service vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.