Description
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to read arbitrary files.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Read
Action: Patch
AI Analysis

Impact

An input validation flaw in macOS allows applications to read arbitrary files by bypassing file access controls. This can let an attacker obtain sensitive data such as configuration files, credentials, or other private information, leading to confidentiality compromise.

Affected Systems

The vulnerability affects Apple macOS in releases that are still using the unpatched input handling, including macOS Golden Gate prior to version 27, macOS Sequoia prior to 15.8, and macOS Tahoe prior to 26.7.

Risk and Exploitability

The CVSS score of 6.5 indicates the vulnerability severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog, implying no known public exploits. Attackers would need to supply crafted input to an affected application or compromise a local user session, so the threat is primarily local or privilege‑local. While the risk of widespread exploitation is low, the potential for data exposure makes timely remediation important.

Generated by OpenCVE AI on September 20, 2026 at 20:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade macOS to at least Golden Gate 27, Sequoia 15.8, or Tahoe 26.7 to apply the fixed input sanitization.
  • Configure application sandboxing or file‑system permissions so the affected applications can access only the directories and files required for normal operation.
  • If an update is not immediately possible, employ network or endpoint controls to prevent installation or execution of untrusted applications that could trigger the vulnerability.

Generated by OpenCVE AI on September 20, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title macOS Arbitrary File Read via Input Validation Flaw

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Arbitrary File Read via Input Validation Flaw in macOS
Weaknesses CWE-20
CWE-200
CWE-22

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Arbitrary File Read via Input Validation Flaw in macOS
Weaknesses CWE-20
CWE-200
CWE-22

Tue, 15 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to read arbitrary files.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T14:36:11.482Z

Reserved: 2026-05-01T22:46:27.820Z

Link: CVE-2026-43791

cve-icon Vulnrichment

Updated: 2026-09-17T14:35:45.484Z

cve-icon NVD

Status : Modified

Published: 2026-09-14T21:17:11.807

Modified: 2026-09-17T15:16:47.003

Link: CVE-2026-43791

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:30:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')