Description
A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious application may be able to access restricted files.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized File Access
Action: Immediate Patch
AI Analysis

Impact

A permissions validation flaw has been corrected in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, indicating that prior to those releases a malicious application could bypass file system permissions and read files it was not authorized to access. The vulnerability results from insufficient privilege checks when accessing restricted files, allowing an attacker to gain unintended data visibility. This could lead to compromise of confidential information or facilitate further attacks if the attacker obtains additional system insights.

Affected Systems

Apple macOS versions 27 (Golden Gate), 15.8 (Sequoia), and 26.7 (Tahoe) are affected by this permissions issue. Users running these releases are at risk when executing validation controls.

Risk and Exploitability

The likely attack vector is a local attacker who can supply or run a malicious application on the system. Based on the description, it is inferred that the vulnerability can be exploited to bypass file-system permissions. An EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The recommended mitigation is to install the patched macOS releases, which resolve the permission checks, thereby eliminating the pathway for unauthorized file access.

Generated by OpenCVE AI on September 20, 2026 at 18:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 to apply the vendor fix
  • Enable Gatekeeper and configure application signing enforcement to prevent untrusted apps from running
  • Review system logs for unusual file access and establish audit policies to detect potential misuse

Generated by OpenCVE AI on September 20, 2026 at 18:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Title Permission Validation Flaw Enables Unauthorized File Access in macOS

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Wed, 16 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Title Malicious Application Gains Unauthorized File Access Due to Permissions Validation Flaw
Weaknesses CWE-284

Tue, 15 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Malicious Application Gains Unauthorized File Access Due to Permissions Validation Flaw
Weaknesses CWE-284

Tue, 15 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious application may be able to access restricted files.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T14:10:55.425Z

Reserved: 2026-09-01T21:13:17.753Z

Link: CVE-2026-84559

cve-icon Vulnrichment

Updated: 2026-09-17T13:39:05.315Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:31.963

Modified: 2026-09-17T14:25:23.807

Link: CVE-2026-84559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:15:17Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure