Description
A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to bypass Gatekeeper checks.
Published: 2026-09-14
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Bypass of Gatekeeper enabling execution of malicious code
Action: Upgrade OS
AI Analysis

Impact

The vulnerability is a logic issue in Gatekeeper, Apple's binary protection system. It permits an application that would otherwise be blocked from execution to bypass Gatekeeper checks, thereby enabling the installation or launch of unsigned or otherwise untrusted software. The flaw stems from improper control over the Gatekeeper authorization process (CWE‑693). If exploited, a user could run arbitrary code from a malicious application without providing explicit consent, potentially leading to data theft, malware installation, or other integrity violations.

Affected Systems

Apple macOS systems running macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 are affected. The vulnerability is fixed in these versions and all later releases. Users of earlier or unpatched releases remain at risk until the appropriate OS update is installed.

Risk and Exploitability

Exploitation requires a local attacker to supply or otherwise install the malicious application on the target machine, indicating a local attack vector. The CVSS score of 4.4 reflects moderate severity, while the EPSS score of less than 1% shows that the probability of exploitation in the wild is very low. The vulnerability is not listed in the CISA KEV catalog. The likely vector is a compromised or malicious application that deliberately circumvents Gatekeeper during installation or launch.

Generated by OpenCVE AI on September 20, 2026 at 20:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update macOS to at least Golden Gate 27, Sequoia 15.8, or Tahoe 26.7, or any newer release that contains the fix.
  • Reboot the system after updating to ensure Gatekeeper checks are applied.
  • Verify that Gatekeeper is enabled by checking System Settings > Security & Privacy > General and ensuring the "Allow apps downloaded from" option is set to "App Store and identified developers."

Generated by OpenCVE AI on September 20, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Gatekeeper Check Bypass Allows Unsigned App Execution

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Logic flaw that enables bypass of Gatekeeper on macOS
Weaknesses CWE-285

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Logic flaw that enables bypass of Gatekeeper on macOS
Weaknesses CWE-285

Tue, 15 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to bypass Gatekeeper checks.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T15:25:49.511Z

Reserved: 2026-09-01T21:13:17.755Z

Link: CVE-2026-84570

cve-icon Vulnrichment

Updated: 2026-09-17T15:25:42.660Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:33.207

Modified: 2026-09-17T16:56:03.390

Link: CVE-2026-84570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:30:05Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure