Junglewise Threat Intelligence

CVE-2026-39874: Apple macOS privilege escalation via permissions issue

CVE-2026-39874 · Severity: info · Published 2026-07-27

Technologies: Apple macOS Tahoe. Vendors: Apple.

Executive brief

A security vulnerability in macOS could allow a malicious application to gain full administrative (root) control over a computer. This would give the attacker complete access to all files, settings, and hardware on the system. Apple has released software updates to address this issue by implementing stricter permission requirements.

Technical details

A privilege escalation vulnerability exists in macOS due to insufficient permission restrictions. A local malicious application can exploit this flaw to bypass security controls and elevate its privileges to root. The vulnerability was addressed by implementing additional restrictions on how permissions are handled within the operating system. The fix is available in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. An attacker must have the ability to execute code on the target system to exploit this issue.

Affected products

  • Apple macOS Sequoia Before 15.7.8
  • Apple macOS Sonoma Before 14.8.8
  • Apple macOS Tahoe Before 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats