Description
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation to Root
Action: Immediate Patch
AI Analysis

Impact

A permission-related vulnerability was found in Apple macOS that enables a malicious application to obtain root privileges. The flaw is mitigated by adding additional restrictions, but unless the fix is applied, an attacker can run code with system‑level access, potentially compromising confidentiality, integrity, and availability of the affected device. This issue is classified an elevation of privilege weakness.

Affected Systems

All macOS releases older than macOS Sequoia 15.7.8 or macOS Tahoe 26.6 contain this vulnerability. Versions preceding these updates are susceptible until the corresponding security update is installed.

Risk and Exploitability

The CVSS score of 7.8 indicates a high impact, and the EPSS score is < 1%, implying a low probability of exploitation. The description indicates that a malicious app can exploit the permission gap to elevate privileges. The vulnerability catalog. Based on the description, the likely attack vector is a malicious application that runs with local or remote code execution capability to gain root access.

Generated by OpenCVE AI on September 17, 2026 at 19:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Apple security update that brings the system to macOS Sequoia 15.7.8 or later, or macOS Tahoe 26.6 or newer.
  • Deploy the update across all managed macOS devices through Apple Business Manager or Apple School Manager to ensure consistent patching.
  • Configure Gatekeeper to allow only signed applications from the App Store or identified developers, reducing executing with elevated privileges.

Generated by OpenCVE AI on September 17, 2026 at 19:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title MacOS Privilege Escalation via Permission Issue

Wed, 16 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title macOS Permission Escalation Vulnerability Leading to Root Privileges

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title macOS Permission Escalation Vulnerability Leading to Root Privileges

Tue, 15 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-280
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T03:56:21.874Z

Reserved: 2026-07-20T18:09:24.049Z

Link: CVE-2026-64701

cve-icon Vulnrichment

Updated: 2026-09-14T22:24:16.376Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:13.577

Modified: 2026-09-15T19:31:12.893

Link: CVE-2026-64701

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:00:16Z

Weaknesses
  • CWE-280

    Improper Handling of Insufficient Permissions or Privileges