Description
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to monitor keystrokes without user permission.
Published: 2026-02-11
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized keystroke monitoring
Action: Update macOS
AI Analysis

Impact

A permissions flaw in macOS Tahoe allows applications to capture keystrokes without explicit user approval, effectively enabling keylogging. This flaw affords an attacker the ability to harvest typed data and sensitive credentials, thereby violating user privacy. The underlying weakness is an access control defect, identified as CWE‑284, which permits privileged data collection under the guise of legitimate input handling.

Affected Systems

The vulnerability exists in macOS Tahoe installations prior to the 26.3 firmware update. Apple has released a patch in macOS Tahoe 26.3 that implements additional restrictions on keystroke monitoring. Users running earlier Tahoe releases, or those that have not applied the latest security update, are susceptible.

Risk and Exploitability

The CVSS score of 3.3 classifies the risk as moderate, and the EPSS score of less than 1 % indicates low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting no widespread or recent exploitation reports. Based on the description, the likely attack vector is a malicious application that either self‑installs or is installed by a user without proper scrutiny, exploiting the permissive monitoring permissions to gather keystrokes unnoticed.

Generated by OpenCVE AI on April 16, 2026 at 06:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to version 26.3 or later to apply the official fix for the keystroke monitoring permission issue.
  • Review Input Monitoring permissions (System Preferences > Security & Privacy > Privacy > Input Monitoring) and remove any applications that do not require keystroke access.
  • Limit software installations to the Mac App Store or trusted developers, and consider disabling or uninstalling any applications that have been granted key‑logging rights without explicit user consent.

Generated by OpenCVE AI on April 16, 2026 at 06:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 16 Apr 2026 07:15:00 +0000

Type Values Removed Values Added
Title macOS Tahoe Keystroke Monitoring Permission Flaw

Wed, 04 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Tue, 17 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Thu, 12 Feb 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Wed, 11 Feb 2026 23:15:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to monitor keystrokes without user permission.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:16:02.641Z

Reserved: 2025-11-11T14:43:07.856Z

Link: CVE-2026-20601

cve-icon Vulnrichment

Updated: 2026-02-17T15:25:49.841Z

cve-icon NVD

Status : Modified

Published: 2026-02-11T23:16:03.907

Modified: 2026-03-04T19:16:18.943

Link: CVE-2026-20601

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T07:00:10Z

Weaknesses