Description
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorization flaw in macOS allows a locally running application to access otherwise protected user data due to improper state management. The issue corresponds to improper authorization (CWE-285). An attacker can read sensitive personal information that should be restricted to an authorized context, potentially exposing confidential data to the malicious application.

Affected Systems

Apple macOS operating systems are impacted when running a version prior to the releases that contain the fix. The flaw was resolved in macOS Sequoia 15.7.8 and macOS Tahoe 26.6, so any machine running an earlier build is vulnerable.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity vulnerability. The EPSS score is less than 1%, showing a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description and available references, the likely attack vector is local: an attacker would need to install or execute a malicious application on the system to benefit from the authorization bypass and read sensitive data.

Generated by OpenCVE AI on August 4, 2026 at 13:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to Sequoia 15.7.8 or newer, or Tahoe 26.6 or newer, to apply the authorization fix.
  • Restrict the installation and execution of third‑party applications and enforce App Sandbox policies to limit the permission scope for untrusted apps.
  • Monitor system logs and application activity for anomalous data reads and investigate any suspicious behavior.

Generated by OpenCVE AI on August 4, 2026 at 13:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Allowing Local App Access to Sensitive User Data on macOS

Mon, 03 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Authorization Flaw Allowing Apps to Access Sensitive User Data in macOS
Weaknesses CWE-284

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Authorization Flaw Allowing Apps to Access Sensitive User Data in macOS
Weaknesses CWE-284
CWE-285
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:36:58.146Z

Reserved: 2026-05-01T22:46:27.818Z

Link: CVE-2026-43775

cve-icon Vulnrichment

Updated: 2026-07-28T14:36:53.707Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:01.880

Modified: 2026-07-28T20:05:36.170

Link: CVE-2026-43775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:45:03Z

Weaknesses