Description
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to modify protected parts of the file system.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: File System Modification
Action: Upgrade System
AI Analysis

Impact

The vulnerability originates from missing entitlement checks and missing authorization in macOS, allowing a non‑privileged application to modify protected parts of the file system. This represents a weakness identified as CWE‑862. The ability to alter system files compromises integrity and may enable further malicious actions.

Affected Systems

Apple macOS is affected in all releases prior to macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, which contain the fix for this issue. Therefore any older macOS version before those releases remains vulnerable.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 5.5 indicates a moderate impact. The likely attack vector is inferred to be user‑initiated execution of a malicious or compromised application that exploits the missing entitlement checks to gain write access to protected file system locations.

Generated by OpenCVE AI on September 20, 2026 at 18:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade macOS to a version that includes the fix, such as macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7, or any newer release.
  • Configure macOS Gatekeeper to allow only apps from the App Store or identified developers, thereby reducing the likelihood that a malicious application can be installed or run.
  • Perform a filesystem integrity check to detect any unauthorized modifications that might have occurred.

Generated by OpenCVE AI on September 20, 2026 at 18:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title macOS File System Modification Vulnerability from Missing Entitlement Checks

Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title macOS Vulnerability Allows Unprivileged App to Modify Protected File System
Weaknesses CWE-284
CWE-732

Tue, 15 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title macOS Vulnerability Allows Unprivileged App to Modify Protected File System
Weaknesses CWE-284
CWE-732

Tue, 15 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to modify protected parts of the file system.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T14:15:32.296Z

Reserved: 2026-09-01T21:13:17.748Z

Link: CVE-2026-84514

cve-icon Vulnrichment

Updated: 2026-09-17T14:15:13.563Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:27.937

Modified: 2026-09-18T16:39:02.157

Link: CVE-2026-84514

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:30:03Z

Weaknesses