Impact
A permissions validation flaw has been corrected in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, indicating that prior to those releases a malicious application could bypass file system permissions and read files it was not authorized to access. The vulnerability results from insufficient privilege checks when accessing restricted files, allowing an attacker to gain unintended data visibility. This could lead to compromise of confidential information or facilitate further attacks if the attacker obtains additional system insights.
Affected Systems
Apple macOS versions 27 (Golden Gate), 15.8 (Sequoia), and 26.7 (Tahoe) are affected by this permissions issue. Users running these releases are at risk when executing third‑party applications that may exploit the flawed access validation controls.
Risk and Exploitability
The flaw is most likely exploitable by a local attacker who can supply or run a malicious application on the system. No CVSS score or EPSS value is currently reported, and the vulnerability is not listed in CISA KEV, indicating that while the potential for impact is significant for privileged data exposure, exploitation in the wild may not yet be widespread. The recommended mitigation is to install the patched macOS releases, which resolve the permission checks, thereby eliminating the pathway for unauthorized file access.
OpenCVE Enrichment