Description
This issue was addressed through improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Update
AI Analysis

Impact

An improper state‑management flaw in macOS allows a malicious or already‑installed application to read sensitive user data that it should not access. The vulnerability was corrected in macOS Golden Gate 27 and can lead to the exposure of private information without requiring elevated privileges.

Affected Systems

Apple macOS is affected, with the vulnerable versions being all releases prior to macOS Golden Gate 27.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that a widespread, automated exploitation campaign has not yet been observed. However, without a hard‑coded CVSS score, the risk remains uncertain, but the nature of the flaw indicates that local or remote applications could potentially exploit it if state information is incorrectly handled. The lack of an official workaround means that the only confirmed mitigation is upgrading to the patched macOS version.

Generated by OpenCVE AI on September 15, 2026 at 10:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to version 27 or later, ensuring the state‑management fix is installed
  • Verify that all third‑party applications are updated to their latest releases to eliminate the possibility of similar state issues
  • If immediate upgrade is not possible, isolate the device from untrusted processes and monitor for abnormal access to sensitive data
  • Check system logs for unauthorized state changes or attempts to read protected information
  • Apply any additional system security settings that restrict application access to user data based on least‑privilege principles

Generated by OpenCVE AI on September 15, 2026 at 10:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title State Management Flaw Enables App Access to Sensitive User Data
Weaknesses CWE-200

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:52:00.649Z

Reserved: 2026-03-03T16:36:03.989Z

Link: CVE-2026-28937

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:05.607

Modified: 2026-09-14T21:17:05.607

Link: CVE-2026-28937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T10:30:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor