Description
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27. An app may be able to modify Privacy preferences.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Modification of Privacy Preferences
Action: Patch Soon
AI Analysis

Impact

A permission oversight allows an installed application to change the system’s privacy settings. This improper access control flaw can enable an attacker to toggle privacy controls, potentially exposing personal data or facilitating other attacks that rely on altered privacy behavior. The vulnerability stems from a lack of adequate permission checks before modifying privacy preference files.

Affected Systems

Apple macOS users with operating system versions older than macOS Golden Gate 27 are vulnerable. The fix was deployed in macOS Golden Gate 27, so only installations pre‑2026 versions face this issue.

Risk and Exploitability

The CVSS base score of 5.5 indicates a medium severity, reflecting the potential privacy impact without confirming widespread compromise. The EPSS score of less than 1% suggests a low probability of exploitation under current threat conditions. The flaw is not listed in CISA’s KEV catalog. Based on the description, the attack surface is local; an application running with sufficient user privileges may exploit this degraded permission check. While not currently a high‑risk public threat, the ability to alter privacy configurations warrants timely remediation.

Generated by OpenCVE AI on September 20, 2026 at 23:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the macOS Golden Gate 27 or later update to enforce the corrected permission checks.
  • Limit application installations to trusted sources and review app permissions in System Settings to reduce the likelihood of an unauthorized app exploiting the flaw.
  • Monitor the privacy preference panel for unexpected changes, and revert or alert users if modifications occur outside of expected application behavior.

Generated by OpenCVE AI on September 20, 2026 at 23:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 21 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Privilege Modification of macOS Privacy Preferences

Sun, 20 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Application Can Modify Privacy Preferences Due to Permission Flaw
Weaknesses CWE-284

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Application Can Modify Privacy Preferences Due to Permission Flaw
Weaknesses CWE-284

Tue, 15 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27. An app may be able to modify Privacy preferences.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T19:28:26.421Z

Reserved: 2026-09-01T21:13:17.757Z

Link: CVE-2026-84589

cve-icon Vulnrichment

Updated: 2026-09-16T19:27:16.770Z

cve-icon NVD

Status : Modified

Published: 2026-09-14T21:17:34.990

Modified: 2026-09-16T20:17:35.197

Link: CVE-2026-84589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses