Description
An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Exposure
Action: Update macOS
AI Analysis

Impact

The vulnerability is an improper authorization flaw that allows a sandboxed application to read the system pasteboards, which normally should be protected; an attacker can therefore retrieve sensitive user data such as copied text, images, or clipboard history, leading to unauthorized disclosure of personal or corporate information.

Affected Systems

Apple macOS releases older than Golden Gate 27 are affected because they lack the additional sandbox restrictions on system pasteboard access; all versions before this update are susceptible.

Risk and Exploitability

With a CVSS score of 5.5 and an EPSS of less than 1%, the risk is moderate but the likelihood of exploitation is low; the flaw does not appear in CISA’s KEV catalog and is likely to be exploited locally by a sandboxed application that can invoke pasteboard APIs during a user session.

Generated by OpenCVE AI on September 20, 2026 at 18:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the macOS update to Golden Gate 27 or later to install the additional sandbox restrictions on system pasteboards.
  • Review installed applications and ensure that only necessary programs have pasteboard access permissions; remove or sandbox any third‑party utilities that request unnecessary pasteboard interactions.
  • Monitor macOS system logs for anomalous pasteboard read events to detect potential misuse by unapproved applications.

Generated by OpenCVE AI on September 20, 2026 at 18:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 20 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Sandbox Escalation via System Pasteboard Access

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Wed, 16 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Sensitive Data Exposure via System Pasteboard Access Due to Insufficient Sandbox Restrictions
Weaknesses CWE-200
CWE-285

Tue, 15 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Sensitive Data Exposure via System Pasteboard Access Due to Insufficient Sandbox Restrictions
Weaknesses CWE-200
CWE-285

Tue, 15 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T17:12:33.321Z

Reserved: 2026-09-01T21:13:17.755Z

Link: CVE-2026-84569

cve-icon Vulnrichment

Updated: 2026-09-17T16:01:34.034Z

cve-icon NVD

Status : Modified

Published: 2026-09-14T21:17:33.110

Modified: 2026-09-17T18:17:10.717

Link: CVE-2026-84569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:00:04Z

Weaknesses