Executive brief
A security vulnerability in macOS could allow a malicious application to gain full administrative (root) control over a computer. This issue stems from how the operating system handles directory paths. If exploited, an attacker could bypass security restrictions to access sensitive data or modify system settings. Apple has released software updates to address this risk.
Technical details
A privilege escalation vulnerability exists in macOS due to a parsing issue in the handling of directory paths. The root cause is insufficient path validation, which can be exploited by a local application to elevate its privileges to root. The attack requires the execution of a malicious app on the target system. Apple addressed this vulnerability by implementing improved path validation logic. The fix is available in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Affected products
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Sonoma Before 14.8.8
- Apple macOS Tahoe Before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory
- 2026-07-27: patched