AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-43679

LOW · CVSS 2.4 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

A vulnerability exists in certain versions of watchOS that allows an attacker with physical access to a locked Apple Watch to bypass permissions and view user contacts. This poses a significant privacy risk for users, particularly in environments where sensitive information is handled. Organizations and individuals using affected Apple Watch models should prioritize updating to watchOS 26.4 to mitigate this risk.

CVE
CVE-2026-43679
Severity
LOW
CVSS
2.4
EPSS
0.12%

Original NVD Description

This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to view user contacts.

Related CVEs

Other vulnerabilities affecting the same vendor(s)