Description
A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access local network devices without user consent.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Local Network Device Access without User Consent
Action: Patch Immediately
AI Analysis

Impact

A permissions flaw in Apple macOS allows an application to access local network devices without receiving explicit user consent. The flaw arose from insufficient state management that failed to enforce proper access controls, enabling unauthorized network interaction. This can expose sensitive device information or allow control of modern networking equipment, potentially compromising the confidentiality and integrity of the local network.

Affected Systems

Apple macOS before version 27 (Golden Gate) is affected. Any macOS installation that has not been updated to Golden Gate 27 or later may allow a malicious or untrusted application to exploit the permissions issue.

Risk and Exploitability

A CVSS score of 5.5 indicates moderate severity, and the EPSS score of < 1% shows a very low exploitation probability. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker might distribute a malicious macOS application that, once installed, can scan or communicate with local network devices without the user's knowledge, because the flaw involves insufficient state management of network permissions. This inference assumes that the attacker can provide a user‑installed app. The potential impact is that unauthorized network access could be achieved across the local environment.

Generated by OpenCVE AI on September 20, 2026 at 21:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the system to macOS Golden Gate 27 or a later release, which implements the fixed state‑management policy.
  • Reboot the device after installing the update so that the new permission model takes effect.
  • Review and remove any installed applications that have obtained network permissions prior to the update; consider revoking network access for remaining apps through System Settings > Privacy > Network if available.

Generated by OpenCVE AI on September 20, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 20 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Network Access without User Consent via Permissions Issue

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Wed, 16 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Local Network Device Access Without User Consent
Weaknesses CWE-284

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Local Network Device Access Without User Consent
Weaknesses CWE-284

Tue, 15 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access local network devices without user consent.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T15:00:07.425Z

Reserved: 2026-09-01T21:13:17.757Z

Link: CVE-2026-84585

cve-icon Vulnrichment

Updated: 2026-09-16T14:59:58.423Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:34.587

Modified: 2026-09-16T15:27:08.020

Link: CVE-2026-84585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:30:06Z

Weaknesses