Junglewise Threat Intelligence

CVE-2026-20696: An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS

CVE-2026-20696 · Severity: medium · CVSS 5.5 · Published 2026-05-11

Technologies: Apple macOS. Vendors: Apple.

Executive brief

An authorization vulnerability in macOS Tahoe could allow a malicious application to access sensitive user data. This issue stems from how the system manages internal states during authorization requests. Users are advised to update to macOS Tahoe 26.4 to protect their private information from unauthorized app access.

Technical details

An authorization vulnerability (CVE-2026-20696) existed in macOS Tahoe due to improper state management. A local application could exploit this flaw to bypass intended authorization boundaries and gain access to sensitive user information. The root cause was identified as a logic error in how the system tracks authorization states, which has been resolved in macOS Tahoe 26.4 through improved state management logic. While the attack requires a malicious app to be present on the system, it poses a significant privacy risk by exposing protected user data.

Affected products

  • Apple macOS Tahoe Before 26.4

Timeline

  • 2026-03-24: patched: Fixed in macOS Tahoe 26.4
  • 2026-05-11: disclosed: Initial advisory publication

References

Related threats