Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Root Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The issue is an out‑of‑bounds write that allows a malicious application to write beyond buffer limits. This flaw can be leveraged to gain root privileges on affected macOS systems. If successful, an attacker could modify system files, install persistence mechanisms, and compromise confidentiality, integrity, and availability.

Affected Systems

Apple macOS products are impacted. The vulnerability is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Systems running these releases or later are safe.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score of < 1 % shows a very low yet measurable exploitation probability. This flaw is not listed in the CISA KEV catalog, so there are no reported active attacks. The likely attack vector is local, where an attacker can execute or install a malicious application containing the vulnerable code. Privilege escalation would require the vulnerable code to run with unprivileged privileges, after which the out‑of‑bounds write can elevate the process to system level.

Generated by OpenCVE AI on September 20, 2026 at 20:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade macOS to at least macOS Golden Gate 27, macOS Sequoia 15.8 or macOS Tahoe 26.7 or later.
  • Ensure Gatekeeper is enabled to block installation of unsigned or untrusted applications.
  • Stay informed by regularly checking Apple Security Advisories for new updates or additional mitigations.

Generated by OpenCVE AI on September 20, 2026 at 20:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Root Privilege Escalation via Out‑of‑Bounds Write in macOS

Wed, 16 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in macOS Allows Root Privilege Escalation

Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in macOS Allows Root Privilege Escalation

Tue, 15 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T03:56:26.181Z

Reserved: 2026-09-01T21:13:17.748Z

Link: CVE-2026-84505

cve-icon Vulnrichment

Updated: 2026-09-14T22:31:24.530Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:27.077

Modified: 2026-09-16T01:08:15.750

Link: CVE-2026-84505

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:45:03Z

Weaknesses