Description
A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to sensitive user data
Action: Apply Patch
AI Analysis

Impact

A permissions issue was addressed with improved validation. This issue allows an application to read sensitive user data beyond intended access controls.

Affected Systems

Apple macOS. The vulnerability applies to macOS versions prior to Golden Gate 27, Sequoia 15.8, and Tahoe 26.7.

Risk and Exploitability

The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. An attacker can use a malicious or compromised application installed on the target system to read protected information by bypassing standard permission checks. The attack requires local execution of the application; no remote execution is required, but the impact is moderate to high for affected systems until the patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 19:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest macOS updates (Golden Gate 27, Sequoia 15.8, Tahoe 26.7) which include the permission validation fix.
  • Verify that all installed apps are from trusted sources and have not been tampered with.
  • Enable and monitor App Sandbox and Gatekeeper to restrict unauthorized access to sensitive data.

Generated by OpenCVE AI on September 20, 2026 at 19:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title macOS Permissions Issue Allowing Unauthorized Data Access

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 16 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Permissions Issue Allows App to Access Sensitive User Data
Weaknesses CWE-284

Tue, 15 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Permissions Issue Allows App to Access Sensitive User Data
Weaknesses CWE-284

Tue, 15 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T17:05:43.566Z

Reserved: 2026-07-22T00:45:26.179Z

Link: CVE-2026-65342

cve-icon Vulnrichment

Updated: 2026-09-17T17:03:49.383Z

cve-icon NVD

Status : Modified

Published: 2026-09-14T21:17:19.050

Modified: 2026-09-17T18:16:59.470

Link: CVE-2026-65342

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:45:02Z

Weaknesses