Executive brief
A security vulnerability in macOS Tahoe could allow a malicious application to gain full administrative (root) control over a computer. This would allow the app to bypass security protections, access all user data, and modify system files. Users should update to macOS Tahoe 26.5 to protect their systems.
Technical details
An information leakage and authorization vulnerability exists in macOS Tahoe that allows a local application to escalate privileges to root. The vulnerability stems from insufficient validation and state management within the system. An attacker can exploit this by running a malicious application on the target system to gain full administrative access. Apple addressed this issue in macOS Tahoe 26.5 by implementing additional validation and improved state management.
Affected products
- Apple macOS Tahoe Before 26.5
Timeline
- 2026-05-11: patched: Fixed in macOS Tahoe 26.5
- 2026-05-11: disclosed