Description
An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Sandbox escape potentially leading to privilege escalation
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is an authorization issue arising from improper state management that allows an application to escape its sandbox boundaries. By breaking out of the sandbox, the compromised app could gain unrestricted access to system resources, leading to integrity and confidentiality risks.

Affected Systems

The issue affects Apple macOS, specifically versions up to and including macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Risk and Exploitability

No public EPSS score or KEV listing is available, but the described sandbox escape implies a high potential for exploitation. The likely attack vector involves a malicious or compromised application executing within the user's environment, with the flaw enabling it to override sandbox restrictions. Due to the absence of explicit vector data, it is inferred that exploitation requires local execution of a targeted application.

Generated by OpenCVE AI on September 15, 2026 at 08:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install macOS updates that include the authorization fix (macOS Golden Gate 27, Sequoia 15.8, or Tahoe 26.7 or later).
  • Verify that all third‑party applications are from trusted sources and consider disabling or uninstalling those that may be compromised.
  • Enable macOS System Integrity Protection and review sandbox audit logs for anomalous behavior.

Generated by OpenCVE AI on September 15, 2026 at 08:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Authorization Issue Allows App to Break Out of Sandbox in macOS
Weaknesses CWE-284

Tue, 15 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:51:00.056Z

Reserved: 2026-09-01T21:13:17.750Z

Link: CVE-2026-84535

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:29.950

Modified: 2026-09-14T21:17:29.950

Link: CVE-2026-84535

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T09:00:16Z

Weaknesses