Description
A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Patch Update
AI Analysis

Impact

The vulnerability is a permissions issue that allows an application to read sensitive user data without proper authorization. It is a moderate severity flaw (CVSS 5.5) and is classified as CWE-863. If an attacker can install or run a malicious application, that application may be able to access data it is not permitted to read, exposing private information.

Affected Systems

Apple macOS users running any release earlier than macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 are vulnerable. The issue is resolved in those releases and any subsequent updates.

Risk and Exploitability

The EPSS score indicates a very low probability of exploitation (< 1 %). The CVSS score of 5.5 reflects moderate impact for unauthorized data access. The flaw is not listed in the CISA KEV catalog, suggesting no widespread exploitation publicly known. An attacker would typically need to deliver or run an untrusted application, which could then read privileged data bypassing normal permission checks due to the flawed authorization logic.

Generated by OpenCVE AI on September 20, 2026 at 21:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade macOS to macOS Golden Gate 27, Sequoia 15.8, or Tahoe 26.7 or newer to apply the fix
  • If an upgrade is not possible immediately, restrict third‑party applications and review app permissions to limit unnecessary access to sensitive data
  • Ensure System Integrity Protection remains enabled to enforce application sandboxing and guard against privilege escalation

Generated by OpenCVE AI on September 20, 2026 at 21:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Sun, 20 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Permission Validation Issue Allowing Unauthorized Access to Sensitive User Data in macOS

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Permissions Issue Allowing App to Access Sensitive User Data
Weaknesses CWE-284

Tue, 15 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Permissions Issue Allowing App to Access Sensitive User Data
Weaknesses CWE-284

Tue, 15 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T15:48:43.950Z

Reserved: 2026-09-01T21:13:23.286Z

Link: CVE-2026-84618

cve-icon Vulnrichment

Updated: 2026-09-17T15:48:29.178Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:36.760

Modified: 2026-09-23T19:08:31.547

Link: CVE-2026-84618

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:30:06Z

Weaknesses