Description
An issue existed in the handling of snapshots. The issue was resolved with improved permissions logic. This issue is fixed in macOS Golden Gate 27. An app may be able to access protected user data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Protected User Data
Action: Patch Immediately
AI Analysis

Impact

An issue in the handling of snapshots could allow an application to read protected user data due to insufficient permission checks (CWE‑284). The flaw permits an app to bypass normal safeguards and access confidential files normally protected within the user’s account. Because the problem resides in snapshot logic, any software that creates or retrieves snapshots could be used to retrieve sensitive information.

Affected Systems

Apple macOS is affected. The vulnerability was addressed in macOS Golden Gate 27; earlier releases that have not applied the patch remain vulnerable. Users should verify the operating system build and apply the update if they are running a previous version.

Risk and Exploitability

The CVSS score is 5.5, and the EPSS score is <1%, indicating a very low probability of exploitation, but the flaw enables disclosure of protected data, which is a high impact event. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local or bundled application that performs snapshot operations; an attacker would need to deliver or run a malicious app on the affected Mac. Immediate remediation via patch removes the vulnerability; until then, the risk to confidentiality is significant for unsecured data.

Generated by OpenCVE AI on September 20, 2026 at 20:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to macOS Golden Gate 27 or later to apply the fixed permissions logic.
  • Enable automatic Software Update so that future patches are applied promptly.
  • Configure system security (sandbox, parental controls, or similar) to restrict snapshot creation and access for non‑system applications.

Generated by OpenCVE AI on September 20, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 20 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Snapshot Handling Permissions Error Enabling Unauthorized Data Access

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title macOS Snapshot Permission Flaw Allows Unauthorized Access to Protected User Data
Weaknesses CWE-284

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title macOS Snapshot Permission Flaw Allows Unauthorized Access to Protected User Data
Weaknesses CWE-284

Tue, 15 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An issue existed in the handling of snapshots. The issue was resolved with improved permissions logic. This issue is fixed in macOS Golden Gate 27. An app may be able to access protected user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T15:28:51.284Z

Reserved: 2026-07-22T00:46:31.442Z

Link: CVE-2026-65380

cve-icon Vulnrichment

Updated: 2026-09-16T15:28:10.978Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:22.353

Modified: 2026-09-16T17:18:53.630

Link: CVE-2026-65380

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:30:05Z

Weaknesses