Description
A race condition was addressed with improved state handling. This issue is fixed in macOS Golden Gate 27, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service through Unexpected System Termination
Action: Patch OS
AI Analysis

Impact

A race condition in macOS state handling allows an application to trigger an unexpected system termination. The flaw does not provide remote code execution or data disclosure. Its primary impact is a denial‑of‑service by crashing the operating system, resulting in loss of availability.

Affected Systems

Apple macOS is affected. Users running any release earlier than macOS Golden Gate 27 or macOS Tahoe 26.7 remain vulnerable. The fix is incorporated in those two releases and in subsequent updates.

Risk and Exploitability

The CVSS score of 5.5 indicates medium severity. The EPSS score is below 1%, showing a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog and no active exploits have been reported. The likely attack vector is local, requiring an application to trigger the race condition, typically by running with elevated privileges.

Generated by OpenCVE AI on September 20, 2026 at 19:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade macOS to version 27 (Golden Gate) or 26.7 (Tahoe) or later to eliminate the race condition.
  • Monitor system logs for unexpected termination events such as kernel panics that may indicate the race condition is still active.
  • Limit the execution applications that could trigger the race condition until the operating system is patched.

Generated by OpenCVE AI on September 20, 2026 at 19:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Race Condition Causing Unexpected System Termination in macOS

Wed, 16 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title Race Condition Leading to Unexpected System Termination in macOS

Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Race Condition Leading to Unexpected System Termination in macOS
Weaknesses CWE-362

Tue, 15 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with improved state handling. This issue is fixed in macOS Golden Gate 27, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T15:34:07.004Z

Reserved: 2026-07-22T00:46:56.740Z

Link: CVE-2026-65401

cve-icon Vulnrichment

Updated: 2026-09-15T15:34:01.215Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:23.650

Modified: 2026-09-16T01:09:09.463

Link: CVE-2026-65401

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:00:04Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')