Junglewise Threat Intelligence

CVE-2026-28899: Apple macOS Gatekeeper bypass via logic issue

CVE-2026-28899 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Gatekeeper is macOS's security system that verifies apps before allowing them to run, protecting users from malicious or untrusted software. A logic flaw in Gatekeeper's checks could allow an app to bypass this verification and run without proper security validation. This could enable distribution and execution of malicious applications that would normally be blocked.

Technical details

A logic issue in Gatekeeper's validation checks was addressed through improved conditional logic. The vulnerability allows an application to bypass Gatekeeper verification by exploiting flawed decision logic that fails to properly enforce security checks. The attack requires local execution capability (the malicious app must be present on the system or introduced by the user), but once executed, it can circumvent the critical security boundary that normally prevents unsigned or untrusted code from running. This effectively disarms one of macOS's primary defenses against malware distribution. Apple patched this issue across multiple macOS versions including Golden Gate 27, Sequoia 15.8, Tahoe 26.6, and 26.7 by implementing improved validation logic.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.6

Timeline

  • 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6 and 26.7
  • 2026-09-14: disclosed

References

Related threats