Executive brief
A path handling vulnerability in Apple macOS allows a locally installed application to gain root-level system privileges through improved validation of file path handling. An attacker with local access to a vulnerable Mac could exploit this flaw to escalate permissions and take full control of the system, compromising all user data and system integrity.
Technical details
This is a path handling vulnerability affecting macOS that allows privilege escalation to root. The vulnerability was fixed through improved validation of file paths and appears to be related to improper path traversal or symlink handling in the OS kernel or a core system component. The attack requires local access to the system (attack vector: local) and may require user interaction or specific preconditions, though the exact prerequisites are not detailed in the advisory. An attacker exploiting this vulnerability could execute arbitrary code with elevated root privileges, completely compromising system security. Patches are available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched