CVE-2026-43679: Apple watchOS

Low severity, CVSS 2.4. EPSS: 0.2% chance of exploitation in the next 30 days.

This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to view user contacts.

Affected products

  • Apple watchOS: before 26.4 (fixed in 26.4)

Published 2026-08-21. Last modified 2026-08-24.