Description
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access protected user data.
Published: 2026-02-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A permissions flaw allows an application to bypass the additional restriction controls and read protected user data that it should not be able to access. This results in unauthorized software being able to obtain sensitive personal information, thereby compromising the confidentiality of user files and settings.

Affected Systems

Apple macOS versions prior to macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26.3 are affected. The issue was fixed in these releases, so any system running an earlier patch level is vulnerable.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves a local or application‑level attack where a malicious or compromised app is given elevated privileges. No remote network exploitation is explicitly documented, so the risk profile centers on the presence of the vulnerable app on the system.

Generated by OpenCVE AI on August 22, 2026 at 11:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update macOS to version 26.3 or later to apply the approved permission restrictions.
  • Remove or revoke elevated privileges for any third‑party applications that may access protected data.
  • Enable System Integrity Protection or enforce sandbox profiles to limit application access to user data.

Generated by OpenCVE AI on August 22, 2026 at 11:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title macOS Permission Restriction Bypass Enables Unauthorized Access to Protected User Data

Fri, 21 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to access protected user data. A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access protected user data.
References

Thu, 16 Apr 2026 01:30:00 +0000

Type Values Removed Values Added
Title macOS Permission Restriction Bypass Enables Unauthorized Access to Protected User Data

Thu, 12 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Thu, 12 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-277
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Feb 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Wed, 11 Feb 2026 23:15:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to access protected user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-21T00:38:49.792Z

Reserved: 2025-11-11T14:43:07.860Z

Link: CVE-2026-20630

cve-icon Vulnrichment

Updated: 2026-02-12T16:03:32.354Z

cve-icon NVD

Status : Modified

Published: 2026-02-11T23:16:06.510

Modified: 2026-08-21T01:16:58.170

Link: CVE-2026-20630

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T11:30:17Z

Weaknesses
  • CWE-277

    Insecure Inherited Permissions