Description
A permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An app may be able to access user-sensitive data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to user‑sensitive data
Action: Apply patch
AI Analysis

Impact

The vulnerability is a permissions issue (CWE-863) and takes advantage of mis‑configured access controls, allowing a malicious or mis‑configured application to read user‑sensitive data it should not access. It arises from insufficient validation of user privileges, resulting in a breach of confidentiality for the affected system. The issue is addressed in Xcode 27 and macOS Golden Gate 27.

Affected Systems

Apple Xcode versions prior to 27 and Apple macOS Golden Gate prior to 27 are impacted.

Risk and Exploitability

The likely attack vector is through mis‑configured or malicious applications running on the system, as the flaw allows an app to bypass access controls and read protected data. This inference is based on the description of the permission bypass. The EPSS score of <1% indicates a very low but non‑zero likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The potential for data disclosure makes it a notable concern whenever an application can be tricked into reading protected data. The flaw is mitigated by applying the available software updates. The CVSS score of 5.5 indicates moderate severity.

Generated by OpenCVE AI on September 20, 2026 at 18:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Xcode to version 27 or later
  • Upgrade macOS to Golden Gate 27 or later
  • If an immediate update is not possible, restrict application permissions and implement sandboxing to limit data access

Generated by OpenCVE AI on September 20, 2026 at 18:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
References

Sun, 20 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Permissions issue enabling application to access user‑sensitive data

Wed, 16 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apple:xcode:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 16 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title macOS and Xcode Permissions Issue Enabling Access to User Sensitive Data
Weaknesses CWE-284

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title macOS and Xcode Permissions Issue Enabling Access to User Sensitive Data
Weaknesses CWE-284

Tue, 15 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Apple xcode
Vendors & Products Apple
Apple macos
Apple xcode

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An app may be able to access user-sensitive data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-22T20:07:27.256Z

Reserved: 2026-07-22T00:46:44.573Z

Link: CVE-2026-65393

cve-icon Vulnrichment

Updated: 2026-09-22T20:07:27.256Z

cve-icon NVD

Status : Modified

Published: 2026-09-14T21:17:22.983

Modified: 2026-09-22T21:17:30.910

Link: CVE-2026-65393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:45:02Z

Weaknesses