Description
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
Published: 2026-07-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a permissions flaw characterized by CWE‑276, allowing a malicious application to gain privileged access. With root privileges, an attacker could take full control of the system, exfiltrate or modify data, install back‑doors, or launch additional attacks.

Affected Systems

Apple macOS releases prior to the following patched versions are vulnerable: Sequoia versions older than 15.7.8, Sonoma versions older than 14.8.8, and Tahoe versions older than 26.6. All current macOS releases newer than or equal to those patch releases contain the fix.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, and the EPSS score of <1% suggests exploitation is unlikely but not impossible. The flaw is not listed in CISA KEV. A local attacker who can install or execute an application is likely to exploit the flaw to elevate privileges, as no network‑based vector is documented in the available data.

Generated by OpenCVE AI on August 3, 2026 at 15:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to the latest available release that includes the fix (Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6).
  • Enforce Gatekeeper and App Sandbox settings to allow only signed applications, limiting the installation of potentially compromised software.
  • If a system upgrade cannot be performed immediately, isolate the device from critical networks, block external download paths, and monitor for unexpected root‑level processes or privilege escalations.

Generated by OpenCVE AI on August 3, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Root Privilege Escalation via Permissions Issue in macOS

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Root Privilege Escalation via Permissions Issue in macOS

Tue, 28 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-05T13:44:09.794Z

Reserved: 2026-04-07T19:58:20.173Z

Link: CVE-2026-39875

cve-icon Vulnrichment

Updated: 2026-07-27T21:00:23.227Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:16:51.533

Modified: 2026-08-05T14:17:06.253

Link: CVE-2026-39875

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T16:00:07Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions