Description
A certificate validation issue was addressed with improved certificate validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to intercept network traffic.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality breach through network traffic interception
Action: Immediate Patch
AI Analysis

Impact

A flaw in macOS’s certificate validation process allows an attacker positioned on a privileged network segment to intercept network traffic. This vulnerability is a certificate validation error (CWE-295) that jeopardizes confidentiality.

Affected Systems

Apple’s macOS in the Golden Gate series before version 27, Sequoia before 15.8, and Tahoe before 26.7 are affected. The issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 and later releases.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, while the EPSS score of less than 1% signals a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to already have a privileged position on the network; once that condition is met, the attacker may intercept traffic, underscoring the potential for confidential data compromise.

Generated by OpenCVE AI on September 20, 2026 at 19:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.7, or later to apply Apple’s fix
  • Configure network devices to enforce strict certificate pinning or chain validation and reject untrusted certificates
  • Implement monitoring for abnormal TLS handshakes or certificate anomalies that may indicate a man‑in‑the‑middle attack

Generated by OpenCVE AI on September 20, 2026 at 19:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Certificate Validation Flaw Allowing TLS Interception by Privileged Network Attacker

Wed, 16 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Certificate Validation Issue Allows Traffic Interception in macOS

Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Certificate Validation Issue Allows Traffic Interception in macOS
Weaknesses CWE-295

Tue, 15 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A certificate validation issue was addressed with improved certificate validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to intercept network traffic.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T15:23:39.219Z

Reserved: 2026-09-08T16:43:41.872Z

Link: CVE-2026-86889

cve-icon Vulnrichment

Updated: 2026-09-15T15:23:29.755Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:39.860

Modified: 2026-09-16T01:03:23.290

Link: CVE-2026-86889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:00:04Z

Weaknesses
  • CWE-295

    Improper Certificate Validation