Description
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.4. An app may bypass Gatekeeper checks.
Published: 2026-03-25
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A permission flaw in macOS permits applications lacking a proper developer signature to bypass Gatekeeper, enabling local execution of binaries that would otherwise be blocked. The weakness arises from unauthorized changes to file permissions and a failure to enforce Gatekeeper rules correctly, corresponding to CWE-284 (Access Control). Consequently, any user or malicious entity with local access can run unsigned code, undermining the operating system’s integrity safeguards.

Affected Systems

Apple macOS versions released before the 26.4 update are affected. The issue was addressed by adding restrictions in macOS Tahoe 26.4; any build older than 26.4 that has not been patched remains vulnerable.

Risk and Exploitability

The CVSS score of 3.3 indicates a low severity impact when considered alone, and the EPSS score of less than 1% shows that exploitation is currently unlikely. The CVE is not listed in CISA’s KEV catalog. Based on the description, the attack vector is local execution; a user who can place an unsigned application on the system can launch it, bypassing Gatekeeper. While the vulnerability does not grant remote code execution or privilege escalation beyond the app’s requested permissions, it breaks a key defense that normally restricts software origins.

Generated by OpenCVE AI on May 10, 2026 at 16:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply macOS update 26.4 or later using the built‑in Software Update mechanism to fix the permission enforcement flaw
  • Use an Enterprise Configuration Profile to enforce Gatekeeper settings that allow only App Store and Developer ID applications and automatically block unsigned binaries
  • If an immediate update is not possible, restrict user accounts to installations from the App Store only and monitor for unsigned applications; disable the 'Allow apps downloaded from anywhere' setting via System Settings or a profile

Generated by OpenCVE AI on May 10, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 10 May 2026 16:45:00 +0000

Type Values Removed Values Added
Title macOS Gatekeeper Permission Bypass Allows Unsigned Application Execution

Sun, 10 May 2026 15:45:00 +0000

Type Values Removed Values Added
Title macOS Gatekeeper Bypass through Permissions Issue
Weaknesses CWE-732

Sun, 10 May 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 27 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
Title macOS Gatekeeper Bypass through Permissions Issue
Weaknesses CWE-732

Fri, 27 Mar 2026 09:30:00 +0000

Type Values Removed Values Added
Title Gatekeeper Bypass via Permissions Issue
Weaknesses CWE-284
CWE-732

Thu, 26 Mar 2026 14:00:00 +0000

Type Values Removed Values Added
Title Gatekeeper Bypass via Permissions Issue
Weaknesses CWE-284
CWE-732

Thu, 26 Mar 2026 12:30:00 +0000

Type Values Removed Values Added
Title Gatekeeper Bypass via Permissions Issue in macOS
Weaknesses CWE-284

Wed, 25 Mar 2026 22:00:00 +0000

Type Values Removed Values Added
Title Gatekeeper Bypass via Permissions Issue in macOS
Weaknesses CWE-284

Wed, 25 Mar 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 25 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Wed, 25 Mar 2026 01:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.4. An app may bypass Gatekeeper checks.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-05-10T13:03:01.120Z

Reserved: 2025-11-11T14:43:07.873Z

Link: CVE-2026-20684

cve-icon Vulnrichment

Updated: 2026-03-25T15:16:02.130Z

cve-icon NVD

Status : Modified

Published: 2026-03-25T01:17:05.387

Modified: 2026-05-10T14:16:46.587

Link: CVE-2026-20684

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-10T16:30:15Z

Weaknesses