Description
An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Sensitive Data
Action: Apply Update
AI Analysis

Impact

An authorization flaw in macOS, caused by improper state management, permits an application running on the user’s machine to read sensitive information it should not normally access. The vulnerability was fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, and is associated with CWE‑285 (Improper Authorization) and CWE‑863 (Access Control for Sensitive Data). The weakness arises from the operating system’s failure to reset state correctly, allowing a malicious or compromised app to bypass normal permission checks and read protected data.

Affected Systems

Any macOS release older than macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 is affected because those versions lack the state‑management fix introduced in the newer releases.

Risk and Exploitability

The EPSS score is less than 1 %, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, the CVSS score of 5.5 denotes moderate potential impact. An attacker would need to deliver a malicious or credential‑stolen application that the user runs locally; no kernel‑level privilege escalation is required. The resulting compromise is limited to environments where an untrusted application is executed, primarily causing privacy violations by exposing sensitive user data.

Generated by OpenCVE AI on September 20, 2026 at 19:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the macOS system to macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 or later, ensuring the state‑management fix is installed.
  • Install the latest security update from Apple as soon as it becomes available, which includes the authorization patch.
  • Use macOS’s app sandboxing and permission controls to limit the access of unfamiliar applications to sensitive data, and avoid running applications from untrusted sources.

Generated by OpenCVE AI on September 20, 2026 at 19:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Improper State Management Allows Unauthorized Access to Sensitive Data in macOS

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 16 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Improper State Management Allows Unauthorized Access to Sensitive Data in macOS
Weaknesses CWE-285

Tue, 15 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T16:59:11.392Z

Reserved: 2026-07-22T00:46:31.442Z

Link: CVE-2026-65378

cve-icon Vulnrichment

Updated: 2026-09-17T16:11:38.865Z

cve-icon NVD

Status : Modified

Published: 2026-09-14T21:17:22.253

Modified: 2026-09-17T17:16:45.573

Link: CVE-2026-65378

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:00:04Z

Weaknesses