Executive brief
The Accessibility framework in macOS Golden Gate 27 contains a vulnerability that allows applications to access sensitive user data through a permissions bypass. An attacker could exploit this weakness by running a malicious app on a Mac to extract protected information without proper authorization, compromising user privacy.
Technical details
This vulnerability in the Accessibility framework is an authorization issue affecting macOS Golden Gate 27 and earlier versions. The root cause is improper state management in the Accessibility subsystem that fails to properly enforce data protection controls. An attacker must run a malicious application on the target system (local attack vector). The vulnerability allows the app to circumvent Accessibility framework protections and read sensitive user data that should be restricted. The issue was fixed in macOS Golden Gate 27 through improved data protection mechanisms.
Affected products
- Apple macOS Golden Gate 27 and earlier
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixed in macOS Golden Gate 27