Executive brief
A security vulnerability in macOS could allow a malicious application to gain full administrative (root) control over a computer. This would give the app unrestricted access to all files, system settings, and user data. Users should update to the latest versions of macOS Sequoia, Sonoma, or Tahoe to protect their systems.
Technical details
A consistency issue exists in the macOS kernel due to improper state handling. A local application can exploit this vulnerability to bypass authorization checks and escalate privileges to root. The issue was addressed by improving state management within the kernel. The vulnerability affects macOS Sequoia versions prior to 15.7.7, macOS Sonoma versions prior to 14.8.7, and macOS Tahoe versions prior to 26.5. Exploitation typically requires the execution of a malicious application on the target system.
Affected products
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory