Junglewise Threat Intelligence

CVE-2026-28937: Apple macOS Accessibility sensitive data access in Golden Gate 27

CVE-2026-28937 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

The Accessibility framework in macOS Golden Gate 27 contains a vulnerability that allows applications to access sensitive user data through a permissions bypass. An attacker could exploit this weakness by running a malicious app on a Mac to extract protected information without proper authorization, compromising user privacy.

Technical details

This vulnerability in the Accessibility framework is an authorization issue affecting macOS Golden Gate 27 and earlier versions. The root cause is improper state management in the Accessibility subsystem that fails to properly enforce data protection controls. An attacker must run a malicious application on the target system (local attack vector). The vulnerability allows the app to circumvent Accessibility framework protections and read sensitive user data that should be restricted. The issue was fixed in macOS Golden Gate 27 through improved data protection mechanisms.

Affected products

  • Apple macOS Golden Gate 27 and earlier

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in macOS Golden Gate 27

References

Related threats