Description
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of the file system.
Published: 2026-03-25
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of protected file system areas
Action: Apply Update
AI Analysis

Impact

A permissions issue in macOS allowed a malicious or improperly designed application to modify protected parts of the file system, compromising system integrity and potentially enabling further escalation of privileges. The vulnerability is a classic example of improper access control and falls under the CWE-284 category. Once an application can write to these protected locations, it can alter system files or configuration, undermining confidentiality and availability of the operating system. The impact is limited to the local user context that runs the application, but if the application is privileged, the consequences expand to the entire system.

Affected Systems

Apple macOS platforms were affected, including macOS Sequoia prior to version 15.7.5, macOS Sonoma prior to 14.8.5, and macOS Tahoe prior to 26.4. Users on these versions are susceptible to the described file system modification risk.

Risk and Exploitability

The CVSS base score of 5.5 indicates moderate severity, and the EPSS score of less than 1% suggests low likelihood of exploitation in the wild. The vulnerability was mitigated by removing the vulnerable code, and it is not listed in CISA's KEV catalog. Exploitation would require the attacker to run or trick a user into running a malicious application with the appropriate file system access; therefore, local environmental conditions and user behavior influence the risk. No publicly available remote exploitation path was documented, implying that the attack surface is primarily local.

Generated by OpenCVE AI on March 27, 2026 at 21:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update macOS to the latest firmware: macOS Sequoia 15.7.5 or newer, macOS Sonoma 14.8.5 or newer, or macOS Tahoe 26.4 or newer.\nIf immediate OS update is not possible, restrict third‑party applications to only the permissions they require and utilize Managed Preferences to block write access to protected directories.\nMonitor the system for any unexpected file changes using built‑in audit tools or third‑party file integrity monitoring solutions.

Generated by OpenCVE AI on March 27, 2026 at 21:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 29 Mar 2026 20:45:00 +0000

Type Values Removed Values Added
Title Permissions Issue Allowing Modification of Protected File System Parts in macOS
Weaknesses CWE-284

Fri, 27 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
Title macOS Permission Escalation via File System Modification
Weaknesses CWE-284
CWE-732

Fri, 27 Mar 2026 09:30:00 +0000

Type Values Removed Values Added
Title macOS Permission Escalation via File System Modification
Weaknesses CWE-284
CWE-732

Thu, 26 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Thu, 26 Mar 2026 12:30:00 +0000

Type Values Removed Values Added
Title macOS Permission Issue Allowing Modification of Protected File System Areas
Weaknesses CWE-284
CWE-732

Wed, 25 Mar 2026 22:00:00 +0000

Type Values Removed Values Added
Title macOS Permission Issue Allowing Modification of Protected File System Areas
Weaknesses CWE-284
CWE-732

Wed, 25 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Wed, 25 Mar 2026 01:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of the file system.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:08:54.720Z

Reserved: 2026-03-03T16:36:03.981Z

Link: CVE-2026-28892

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2026-03-25T01:17:12.673

Modified: 2026-03-27T20:16:27.437

Link: CVE-2026-28892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-29T20:28:38Z

Weaknesses