Description
A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to access protected user data.
Published: 2026-09-14
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Protected User Data
Action: Apply Patch
AI Analysis

Impact

A race condition (CWE‑362) is described where concurrent processes can access and modify shared data simultaneously, allowing a malicious or poorly behaved application to read protected user data. The description notes that Apple added validation checks in macOS Tahoe 26.6 to prevent the timing issue that enables the data exposure. The flaw permits read‑only access to confidential information but does not explicitly state privilege escalation or remote execution.

Affected Systems

The advisory indicates the fix is only applied in macOS Tahoe 26.6; therefore, it is inferred that all earlier releases of Apple macOS are potentially vulnerable, even though the exact versions are not enumerated. Users running any macOS version before 26.6 should consider themselves at risk.

Risk and Exploitability

The CVSS score of 4.7 signals moderate severity, while the EPSS score of less than 1 % reflects a very low probability of exploitation. The issue is not listed in the CISA KEV catalog. The description implies that exploitation likely requires an application to be executed locally on the affected system to trigger the race condition, as the vulnerability is triggered by concurrent, local processes. The impact is a confidentiality breach through read‑only exposure of protected data. No evidence suggests remote access or privilege escalation is necessary.

Generated by OpenCVE AI on September 20, 2026 at 19:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade macOS to version 26.6 or later to receive the race‑condition fix.
  • Enable automatic system updates to ensure future security patches are applied promptly.
  • Restrict the installation of third‑party applications that request elevated access to protected user data until a patch is available.

Generated by OpenCVE AI on September 20, 2026 at 19:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 20 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Race Condition Allowing Access to Protected User Data in macOS

Thu, 17 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 16 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title Race Condition Allowing Access to Protected User Data

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Race Condition Allowing Access to Protected User Data
Weaknesses CWE-362

Tue, 15 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to access protected user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T15:08:44.710Z

Reserved: 2026-09-01T21:13:17.754Z

Link: CVE-2026-84562

cve-icon Vulnrichment

Updated: 2026-09-15T15:08:25.839Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:32.283

Modified: 2026-09-17T15:58:53.037

Link: CVE-2026-84562

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:15:03Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')