Description
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access protected user data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Protected User Data
Action: Apply patch
AI Analysis

Impact

A permissions issue in macOS allows applications to read protected user data that they should not be able to access. This flaw effectively grants an application elevated privileges to sensitive information, leading to potential confidentiality violations. The weakness is an example of improper access control (CWE‑269).

Affected Systems

Apple macOS versions affected include Golden Gate 27, Sequoia 15.8, and Tahoe 26.7. Newer releases are not mentioned.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, and the EPSS score of < 1% shows a low probability of exploitation. This vulnerability is not listed in the CISA KEV catalog. An attacker who can install or run a malicious application on the target system might exploit the permission lapse to read protected user data. The likely attack vector is local, as it requires legitimate execution of the app on the machine.

Generated by OpenCVE AI on September 20, 2026 at 19:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade macOS to the latest security‑patched release, specifically Golden Gate 27 or later, Sequoia 15.8 or later, or Tahoe 26.7 or later.
  • Restrict permissions for applications that are not required to access protected data, reviewing the app settings and revoking unnecessary access.
  • Enable and review system‑wide privacy controls, ensuring that only approved applications have read access to sensitive user information.
  • Monitor system logs for signs of unauthorized data access and conduct regular audit reviews.

Generated by OpenCVE AI on September 20, 2026 at 19:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Permission Issue Allowing Apps to Access Protected User Data

Thu, 17 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title macOS Permissions Issue Allows App to Access Protected User Data
Weaknesses CWE-284

Tue, 15 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title macOS Permissions Issue Allows App to Access Protected User Data
Weaknesses CWE-284

Tue, 15 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access protected user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T15:05:14.897Z

Reserved: 2026-09-01T21:13:17.757Z

Link: CVE-2026-84587

cve-icon Vulnrichment

Updated: 2026-09-17T15:05:09.322Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:34.783

Modified: 2026-09-17T16:54:29.953

Link: CVE-2026-84587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:00:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management