Description
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious application may be able to bypass Privacy preferences.
Published: 2026-07-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local authorization flaw in macOS permits a malicious application to override user‑configured privacy preferences. The vulnerability stems from insufficient state‑management checks, allowing an app to modify privacy settings without the user's consent and potentially expose personal data. This leads to an unintended privilege escalation where the application gains broader rights than intended.

Affected Systems

Apple macOS versions prior to the advertised fixes are affected. Specifically, macOS Sequoia before 15.7.8, macOS Sonoma before 14.8.8, and macOS Tahoe before 26.6 are vulnerable. The issue is resolved in the patched releases mentioned.

Risk and Exploitability

The CVSS score of 7.1 highlights a moderate to high severity, while the EPSS score of less than 1% indicates a low expected exploitation probability. The vulnerability is not listed in the CISA KEV catalog, implying no documented widespread exploitation. The likely attack vector is a malicious local application that has already acquired the ability to run on the system; such an app can exploit the bypass to modify privacy settings without user awareness.

Generated by OpenCVE AI on August 4, 2026 at 13:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to the latest official release—macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, or macOS Tahoe 26.6, which contain the fix for the authorization issue.
  • Remove or quarantine any untrusted or unknown applications that could exploit the flaw, and run a malware scan on the system.
  • Regularly review the Privacy preferences panel to detect and revert any unauthorized changes, and enable system integrity protection to limit privileged application modifications.

Generated by OpenCVE AI on August 4, 2026 at 13:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Permitting Unauthorized Privacy Preference Modifications on macOS

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Allowing Privacy Preference Override in macOS
Weaknesses CWE-269
CWE-284

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Allowing Privacy Preference Override in macOS
Weaknesses CWE-269
CWE-284
CWE-863
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious application may be able to bypass Privacy preferences.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T15:22:49.290Z

Reserved: 2026-05-01T22:46:21.640Z

Link: CVE-2026-43672

cve-icon Vulnrichment

Updated: 2026-07-28T15:22:43.201Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:16:52.553

Modified: 2026-07-29T15:46:50.810

Link: CVE-2026-43672

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:15:03Z

Weaknesses