Description
A permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An application may be able to access restricted files.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized file access
Action: Upgrade OS
AI Analysis

Impact

A permissions issue in macOS allows applications to read or write restricted files because path validation is insufficient. This flaw means that a malicious or compromised application can access data that should be protected by the operating‑system sandbox. The vulnerability involves improper input validation and access control.

Affected Systems

Apple macOS versions that are affected and that contain the flaw include macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Risk and Exploitability

The EPSS score is <1%, indicating a very low likelihood of exploitation. The CVSS score of 5.5 indicates moderate severity, but the flaw is not listed in the CISA KEV catalog, and it remains a local or application‑level vulnerability. The attack is likely to require the attacker to run or manipulate an application on the affected system, after which the application may browse to a disallowed path and read or modify protected files. The risk is elevated for systems that run applications from untrusted sources or that allow users to supply file paths without rigorous sanitization.

Generated by OpenCVE AI on September 21, 2026 at 00:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest macOS updates that include the fixes for Golden Gate 27, Sequoia 15.8, and Tahoe 26.7 or later.
  • If immediate upgrading is not possible, restrict the application’s sandbox rights or move sensitive files to locations with stricter permissions.
  • Audit and enforce stricter path validation or input filtering in any custom applications that may construct file paths.

Generated by OpenCVE AI on September 21, 2026 at 00:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title macOS Path Validation Issue Allowing Unauthorized File Access

Sun, 20 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title macOS Permissions Flaw Allowing Access to Restricted Files via Improper Path Validation
Weaknesses CWE-284

Fri, 18 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title macOS Permissions Flaw Allowing Access to Restricted Files via Improper Path Validation
Weaknesses CWE-22
CWE-284

Tue, 15 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An application may be able to access restricted files.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T12:05:49.041Z

Reserved: 2026-09-08T16:43:41.875Z

Link: CVE-2026-86910

cve-icon Vulnrichment

Updated: 2026-09-16T12:02:21.983Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:41.550

Modified: 2026-09-18T12:07:36.267

Link: CVE-2026-86910

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:30:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')