Description
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A user may be able to elevate privileges.
Published: 2026-07-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a logic flaw that allows a user to elevate privileges on macOS. It is an improper authorization condition that can enable a user to perform actions at a higher privilege level than granted. The impact, as stated, is the ability for a user to gain unauthorized elevated privileges, potentially compromising system security. The weakness corresponds to improper handling of authorization (CWE-693).

Affected Systems

Apple macOS is affected. Versions prior to macOS Sequoia 15.7.8 and prior to macOS Tahoe 26.6 are not yet patched. Users of earlier releases of these macOS versions remain vulnerable.

Risk and Exploitability

Because the issue allows privilege escalation, an attacker could gain root or system level access, enabling full system compromise. The CVSS score is 7.8, indicating high severity. The EPSS score is less than 1%, indicating low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The potential exploit requires legitimate user access to the system and the ability to trigger the logic condition, which may not be trivial. Overall, the risk remains high due to the critical nature of privilege escalation.

Generated by OpenCVE AI on August 4, 2026 at 13:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to at least Sequoia 15.7.8 or Tahoe 26.6, which contain the fix for this logic issue.
  • Configure macOS Role-Based Access Control to restrict privileged commands to administrator users only.
  • Apply network segmentation and least privilege controls to limit potential damage from an elevated privilege scenario.

Generated by OpenCVE AI on August 4, 2026 at 13:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Logic Issue Allowing Privilege Escalation on macOS

Mon, 03 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Logic Issue in macOS
Weaknesses CWE-269
CWE-285

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Logic Issue in macOS
Weaknesses CWE-269
CWE-285
CWE-693
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A user may be able to elevate privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-29T03:55:28.358Z

Reserved: 2026-03-03T16:36:03.984Z

Link: CVE-2026-28912

cve-icon Vulnrichment

Updated: 2026-07-28T14:46:16.521Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:16:49.273

Modified: 2026-07-29T15:45:01.307

Link: CVE-2026-28912

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:45:03Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure