Description
A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious application may bypass Gatekeeper checks.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Bypassing Gatekeeper checks, enabling execution of unauthorized applications
Action: Immediate Update
AI Analysis

Impact

Apple’s macOS Gatekeeper subsystem contains a logic flaw in its state management that can be exploited to bypass authorization checks. An attacker can forge or manipulate the state so that an unsigned or otherwise prohibited application is treated as compliant, allowing it to run with the privileges of the user who launches it and paving the way for further compromise. This weakness is identified as CWE‑693, improper control of a returned value.

Affected Systems

The flaw exists in macOS releases prior to the updates that contain the fix. Users running macOS Golden Gate earlier than version 27, macOS Sequoia prior to 15.8, and macOS Tahoe before 26.7 are affected. All newer releases that include the correction are not vulnerable.

Risk and Exploitability

The CVSS score of 5.5 signals moderate severity while the EPSS score of < 1 % indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Gatekeeper operates as a local security policy, so the most likely attack vector is a local user installing or executing a malicious application that takes advantage of the logic flaw. Remote exploitation without user interaction is conceivable only if the attacker can deliver the compromised application via social engineering or a deceptive download. No special system privileges are required beyond those needed to run a regular application.

Generated by OpenCVE AI on September 20, 2026 at 21:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest macOS update that includes the Gatekeeper fix, at least macOS Golden Gate 27, Sequoia 15.8, or Tahoe 26.7.
  • Ensure that Gatekeeper quarantine flags are consistently set on any downloaded applications, using the xattr utility or equivalent system controls.
  • Review Gatekeeper and security audit logs for any attempts to override application authorization checks, and investigate anomalies promptly.

Generated by OpenCVE AI on September 20, 2026 at 21:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Logic Flaw in macOS Gatekeeper Allows Bypass of Application Authorization Checks

Thu, 17 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Gatekeeper Bypass via Logic Issue
Weaknesses CWE-284

Tue, 15 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Gatekeeper Bypass via Logic Issue
Weaknesses CWE-284

Tue, 15 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious application may bypass Gatekeeper checks.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T12:36:48.160Z

Reserved: 2026-07-22T00:46:16.023Z

Link: CVE-2026-65369

cve-icon Vulnrichment

Updated: 2026-09-16T12:36:25.100Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:21.600

Modified: 2026-09-17T15:59:11.300

Link: CVE-2026-65369

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:30:06Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure