Description
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to gain root privileges.
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from missing entitlement checks that allow a malicious application to perform actions normally restricted to privileged system processes, resulting in the potential acquisition of root with CWE‑280. An app can deliberately exploit these checks to elevate its privileges to system level, compromising confidentiality, integrity, and availability of the affected machine.

Affected Systems

Apple macOS is affected by this flaw; it was resolved in macOS Golden Gate 27. All versions earlier than Golden Gate 27 are vulnerable. The issue affects the entire operating system as it permits unauthorized privilege elevation.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity of potential impact. The EPSS score suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local execution of a malicious application, as the flaw requires the ability to launch an app with certain entitlements. An attacker who can run code on the system can abuse the missing checks to gain root privileges, which considerably increases the risk of a full system compromise.

Generated by OpenCVE AI on September 17, 2026 at 20:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install macOS Golden Gate 27 or any later release that includes the installation untrusted sources and ensure that only signed, trusted applications are granted elevated privileges.
  • Apply the latest Apple security updates and monitor system logs for signs of privilege‑escalation attempts.
  • Enable Gatekeeper and restrict application installations to only signed apps from the App Store or identified developers to prevent unauthorized code from executing with elevated privileges.

Generated by OpenCVE AI on September 17, 2026 at 20:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Missing Entitlement Checks in macOS

Wed, 16 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Root Privilege Escalation via Entitlement Check Bypass in macOS

Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Root Privilege Escalation via Entitlement Check Bypass in macOS

Tue, 15 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-280
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to gain root privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T03:56:20.777Z

Reserved: 2026-09-01T21:13:23.288Z

Link: CVE-2026-84631

cve-icon Vulnrichment

Updated: 2026-09-14T22:23:03.825Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:38.050

Modified: 2026-09-15T17:35:16.410

Link: CVE-2026-84631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:00:16Z

Weaknesses
  • CWE-280

    Improper Handling of Insufficient Permissions or Privileges