Description
A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass Gatekeeper checks.
Published: 2026-09-14
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Gatekeeper Bypass
Action: Apply Update
AI Analysis

Impact

A logic flaw in macOS can allow any application to bypass Gatekeeper verification, enabling the execution of unsigned or other restricted code. The issue stems from an improvement in state management that, while designed to fix a problem, inadvertently allowed applications to falsify Gatekeeper checks. The result is that an application could be executed without the security guarantees normally provided by Gatekeeper. This flaw is identified as affecting application integrity and, to the extent Gatekeeper is relied upon, system integrity as well. description states that an app may be able to bypass Gatekeeper checks, but the exact mechanism for how the logic flaw is triggered is not detailed in the CVE. Thus, while the impact is a Gatekeeper bypass, the specific steps an attacker would need to take are inferred rather than documented.

Affected Systems

Apple’s macOS platform is impacted; all macOS releases prior to the Golden Gate 27 update may allow a Gatekeeper bypass. The vulnerability is present in the operating system irrespective of user profile or additional configuration, as Gatekeeper operates at the OS state‑management layer. Users running earlier macOS versions are potentially susceptible. The CVE description does not specify exact sub‑versions or hardware platforms, so the scope remains broad. Based on the information provided, it is inferred that the vulnerability is not limited to any specific user roles or settings.

Risk and Exploitability

The CVSS score of 4.4 indicates moderate severity, while the EPSS score of less than 1% signals a very low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, suggesting no large‑scale exploitation has been observed to date. The flaw could be triggered by any mechanism that enables an application's execution without Gatekeeper verification, but specific exploit conditions or attack vectors are not disclosed in the available data. Based on the description, it is inferred that the likely attack vector involves an application attempting to execute code that bypasses Gatekeeper checks, though no explicit exploit code or technique is disclosed. The lack of detailed attack vector information represents a knowledge gap.

Generated by OpenCVE AI on September 20, 2026 at 21:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply macOS update to Golden Gate 27 or later to address the state‑management logic flaw.
  • Restart the system after applying the update so that the new Gatekeeper behavior takes effect.
  • Configure Gatekeeper via System Settings or MDM to restrict installations to the App Store and identified developer applications.

Generated by OpenCVE AI on September 20, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 20 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Logic flaw in macOS enables application to bypass Gatekeeper verification
Weaknesses CWE-264
CWE-285

Fri, 18 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Tue, 15 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Logic flaw in macOS enables application to bypass Gatekeeper verification
Weaknesses CWE-264
CWE-285

Tue, 15 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass Gatekeeper checks.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T14:13:03.077Z

Reserved: 2026-09-08T16:43:41.874Z

Link: CVE-2026-86909

cve-icon Vulnrichment

Updated: 2026-09-17T14:04:08.983Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:41.457

Modified: 2026-09-18T13:40:35.320

Link: CVE-2026-86909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:30:06Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure