Executive brief
A logic flaw in macOS affects how the operating system manages state across various components including accounts, permissions, and authentication. An application could exploit this vulnerability to access protected user data such as account information and sensitive personal details. The flaw has been patched in macOS Golden Gate 27, Sequoia 15.8, and Tahoe 26.7.
Technical details
This vulnerability is a state management logic issue affecting multiple macOS subsystems including Accessibility, AppKit, Apple Account, and Apple Intelligence components. The root cause is improper state handling in authorization and permission checks, allowing a malicious or compromised application to bypass intended access controls. The attack requires a local application to be installed and executed on the affected macOS system. An attacker can exploit this to read protected user data and credentials. The issue is fixed in the patched versions released September 14, 2026.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched