Description
A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass Apple Intelligence security prompts.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Security Prompt Bypass
Action: Immediate Patch
AI Analysis

Impact

A permissions flaw in macOS allows an application to bypass Apple Intelligence security prompts, potentially granting elevated privileges or access without user awareness. This weakness can enable an attacker to perform unauthorized actions under the guise of legitimate software permissions, compromising confidentiality and integrity of user data. The vulnerability is tied to improper authorization control.

Affected Systems

Apple macOS versions before Golden Gate 27 are affected. The fix is included in macOS Golden Gate 27, so any macOS installation earlier than 27 requires an update to mitigate the flaw.

Risk and Exploitability

The CVSS score is 5.5, indicating a medium severity, while the EPSS score of <1% indicates a very low likelihood of exploitation, suggesting a low overall risk. Based on the description, the likely attack vector involves an app exploiting the permission error to manipulate prompt handling, which could be initiated from a local user context or a compromised application. The vulnerability is not listed in the CISA KEV catalog, but the presence of a bypass indicates a potential for misuse if exploited.

Generated by OpenCVE AI on September 20, 2026 at 18:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to macOS Golden Gate 27 or later.
  • If immediate update is not possible, install any available vendor patches that address the permission handling fix.
  • Restrict application permissions using Gatekeeper or local security policies to limit multiple exposures to unauthorized prompt bypass attempts.

Generated by OpenCVE AI on September 20, 2026 at 18:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 20 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title macOS Permission Flaw Enabling Security Prompt Bypass

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Permissions Issue Allowing App to Bypass Apple Intelligence Security Prompts
Weaknesses CWE-284

Tue, 15 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Permissions Issue Allowing App to Bypass Apple Intelligence Security Prompts
Weaknesses CWE-284

Tue, 15 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass Apple Intelligence security prompts.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T17:12:14.761Z

Reserved: 2026-09-01T21:13:17.759Z

Link: CVE-2026-84601

cve-icon Vulnrichment

Updated: 2026-09-17T16:01:42.879Z

cve-icon NVD

Status : Modified

Published: 2026-09-14T21:17:35.613

Modified: 2026-09-17T18:17:11.067

Link: CVE-2026-84601

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:00:04Z

Weaknesses