Apple Security Updates – 24 March 2026

Apple has released security updates to address multiple vulnerabilities across macOS Tahoe, Sequoia, Sonoma, and Safari.

The addressed vulnerabilities could allow the attacker to perform denial-ofservice attacks, bypass security restrictions, corrupt memory, execute arbitrary code, and gain unauthorized access to the affected systems, potentially leading to compromise of system integrity and overall security posture.

Sample of the addressed vulnerabilities:

1. Apple macOS Improper Locking Vulnerability (CVE-2025-43510)

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Code Execution

2. Apple Cross-Origin Issue in the Navigation API Vulnerability (CVE-2026-20643)

  • CVSS: 5.4
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Bypass Security

It should be highlighted that security researchers have discovered that the vulnerabilities that have already been patched previously (CVE-2025-31277, CVE- 2025-43510, CVE-2025-43520, CVE-2023-43000) are currently being exploited in the wild.

Vulnerabilities
  • CVE-2026-20643
  • CVE-2025-31277
  • CVE-2025-43510
  • CVE-2025-43520
  • CVE-2023-43000
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Apple Security Advisory

References