Description
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a parsing flaw in macOS’s handling of directory paths, allowing certain applications to bypass normal security checks and read protected files. The flaw results from inadequate path validation, giving an app the ability to access sensitive user data that should otherwise be restricted. The primary impact is the disclosure of confidential information.

Affected Systems

Apple macOS releases Golden Gate 27, Sequoia 15.8, and Tahoe 26.7 are affected, because the prescribed path‑validation logic was not in place in those versions. Users running any of these releases should verify their system version against the listed updates.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% and absence from the CISA KEV list suggest a low exploitation probability. The likely attack vector is an application that accepts user‑supplied path inputs; exploitation requires the attacker to run code within that application’s context or to gain local execution privileges. The patch mitigates the issue by enforcing stricter path validation.

Generated by OpenCVE AI on September 20, 2026 at 19:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade macOS to the latest available release (Golden Gate 27, Sequoia 15.8, or Tahoe 26.7) to apply the fixed path‑validation logic.
  • Verify that all third‑party applications rely on the updated system APIs for path handling and reinstall or replace legacy utilities that use deprecated path‑processing code.
  • Apply sandboxing or enforce application‑level file‑access controls to restrict local applications from reaching sensitive directories where feasible.

Generated by OpenCVE AI on September 20, 2026 at 19:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Path Parsing Vulnerability in macOS Allows Access to Sensitive User Data

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Wed, 16 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Directory Path Traversal Vulnerability in macOS
Weaknesses CWE-20
CWE-22

Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Directory Path Traversal Vulnerability in macOS
Weaknesses CWE-20
CWE-22

Tue, 15 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-20T00:32:16.687Z

Reserved: 2026-07-22T00:46:31.443Z

Link: CVE-2026-65382

cve-icon Vulnrichment

Updated: 2026-09-20T00:31:54.984Z

cve-icon NVD

Status : Modified

Published: 2026-09-14T21:17:22.560

Modified: 2026-09-20T01:16:29.243

Link: CVE-2026-65382

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:45:02Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')