Description
A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious application may be able to access restricted files.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized File Access
Action: Immediate Patch
AI Analysis

Impact

A permissions validation flaw has been corrected in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, indicating that prior to those releases a malicious application could bypass file system permissions and read files it was not authorized to access. The vulnerability results from insufficient privilege checks when accessing restricted files, allowing an attacker to gain unintended data visibility. This could lead to compromise of confidential information or facilitate further attacks if the attacker obtains additional system insights.

Affected Systems

Apple macOS versions 27 (Golden Gate), 15.8 (Sequoia), and 26.7 (Tahoe) are affected by this permissions issue. Users running these releases are at risk when executing third‑party applications that may exploit the flawed access validation controls.

Risk and Exploitability

The flaw is most likely exploitable by a local attacker who can supply or run a malicious application on the system. No CVSS score or EPSS value is currently reported, and the vulnerability is not listed in CISA KEV, indicating that while the potential for impact is significant for privileged data exposure, exploitation in the wild may not yet be widespread. The recommended mitigation is to install the patched macOS releases, which resolve the permission checks, thereby eliminating the pathway for unauthorized file access.

Generated by OpenCVE AI on September 15, 2026 at 08:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 to apply the vendor fix
  • Enable Gatekeeper and configure application signing enforcement to prevent untrusted apps from running
  • Review system logs for unusual file access and establish audit policies to detect potential misuse

Generated by OpenCVE AI on September 15, 2026 at 08:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Malicious Application Gains Unauthorized File Access Due to Permissions Validation Flaw
Weaknesses CWE-284

Tue, 15 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious application may be able to access restricted files.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:52:03.667Z

Reserved: 2026-09-01T21:13:17.753Z

Link: CVE-2026-84559

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:31.963

Modified: 2026-09-14T21:17:31.963

Link: CVE-2026-84559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T09:00:16Z

Weaknesses