Description
A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may bypass Gatekeeper checks.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A file quarantine bypass was addressed with additional checks. The vulnerability permits an application to circumvent Gatekeeper, Apple's macOS security gate that verifies code signatures before execution. By sidestepping these checks, an attacker can run malicious or unsigned code with the privileges of the user or system, potentially compromising confidentiality, integrity, or availability of the machine. This is a CWE‑693 weakness involving improper authorization of application execution.

Affected Systems

Apple macOS systems before the release of macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, or macOS Tahoe 26.6 are affected. These earlier releases lack the additional quarantine checks required to enforce Gatekeeper validation.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in CISA's KEV catalog, indicating no documented public exploits at this time. However, the core weakness – bypassing Gatekeeper – could be leveraged by an attacker to execute code with higher privileges if the system remains unpatched. The CVSS score of 5.5 categorises the vulnerability as medium severity, but the potential for system compromise warrants remediation.

Generated by OpenCVE AI on August 4, 2026 at 13:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the operating system to macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, or macOS Tahoe 26.6 or later to receive the additional quarantine checks that fix the Gatekeeper bypass.
  • Verify that Gatekeeper is enabled in Security & Privacy preferences and set to "Require app verification."
  • Regularly audit installed applications for unsigned or unverified binaries and remove any that are not trusted.

Generated by OpenCVE AI on August 4, 2026 at 13:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Gatekeeper Quarantine Bypass Allowing Unauthorized App Execution

Sun, 02 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title macOS Gatekeeper Integrity Check Bypass Enables Unauthorized App Execution
Weaknesses CWE-295

Thu, 30 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title macOS Gatekeeper Integrity Check Bypass Enables Unauthorized App Execution
Weaknesses CWE-295

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may bypass Gatekeeper checks.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:31:07.991Z

Reserved: 2026-07-20T18:09:24.049Z

Link: CVE-2026-64708

cve-icon Vulnrichment

Updated: 2026-07-28T14:30:55.429Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:10.170

Modified: 2026-07-28T17:57:48.773

Link: CVE-2026-64708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:30:10Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure