Description
A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation to Root
Action: Patch
AI Analysis

Impact

A path handling flaw was found in Apple macOS where inadequate validation could allow an application to manipulate filesystem paths. If exploited, the flaw could grant the application root privileges, providing full control over the affected machine, enabling data tampering, persistence, and other high‑impact consequences.

Affected Systems

Apple macOS Golden Gate, macOS Sequoia, and macOS Tahoe are the affected product families. The issue is resolved in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Systems running earlier releases remain vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.8, which indicates moderate to high severity. The EPSS score is < 1%, suggesting a very low probability of exploitation. The issue is not listed in the CISA KEV catalog. The likely attack vector is local privilege escalation, inferred from the description that an application could gain root privileges. Although no publicly available exploit is known, the potential impact of a successful exploitation remains significant.

Generated by OpenCVE AI on September 16, 2026 at 09:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install macOS updates that include the fix, specifically updating to macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7, or any later release that contains these changes.
  • Restrict execution of untrusted applications by enforcing strict application whitelisting and adopting macOS sandboxing features.
  • Enforce least privilege for user accounts, using role‑based access controls and disabling administrative privileges where not needed.

Generated by OpenCVE AI on September 16, 2026 at 09:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title macOS Path Handling Flaw Allowing Privilege Escalation

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T03:56:22.920Z

Reserved: 2026-05-01T22:46:21.642Z

Link: CVE-2026-43691

cve-icon Vulnrichment

Updated: 2026-09-14T22:24:44.785Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:08.443

Modified: 2026-09-15T19:27:02.680

Link: CVE-2026-43691

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T10:00:15Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')