Description
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
Published: 2026-07-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A permissions flaw allows a malicious app to elevate its privileges to root, giving the attacker full control over the system. This weakness is a classic example of a Permission Modification error (CWE-276) and results in both integrity and confidentiality loss when exploited.

Affected Systems

Apple macOS versions prior to the updates that introduce the fix are affected. The issue is resolved in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6, so any installation of those or earlier releases is susceptible.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score for this vulnerability is < 1%, indicating a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local application executed by a user or automatically loaded scenario; remote exploitation is not documented in the provided data.

Generated by OpenCVE AI on August 3, 2026 at 16:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to at least Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6, which contain the permission restriction fix
  • Restrict the installation of applications to signed apps only and enable Gatekeeper to prevent unsigned or malicious software from running
  • Monitor system logs for unexpected privilege changes and conduct routine security reviews to detect unauthorized activity

Generated by OpenCVE AI on August 3, 2026 at 16:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Permissions Issue in macOS

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Permissions Issue in macOS

Tue, 28 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T03:57:13.809Z

Reserved: 2026-04-07T19:58:20.173Z

Link: CVE-2026-39874

cve-icon Vulnrichment

Updated: 2026-07-27T20:58:04.343Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:16:51.433

Modified: 2026-07-29T15:47:01.370

Link: CVE-2026-39874

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T16:15:03Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions