Executive brief
Apple's macOS operating system contains a permissions flaw in the Accounts framework that could allow a malicious application to escalate privileges to root level. An attacker could exploit this by installing and running a crafted app to gain unauthorized administrative control over the system, potentially compromising all user data and system integrity.
Technical details
This vulnerability is a permissions issue (CVE-2026-64701) in macOS that allows unauthorized privilege escalation. The root cause involves improper access control in the Accounts framework, where a malicious application can bypass sandbox restrictions and gain root-level privileges. The attack requires only local execution of a malicious app with no additional preconditions. An attacker can achieve full system compromise with elevated privileges. The issue is patched in macOS Sequoia 15.7.8 and macOS Tahoe 26.6, released July 27, 2026.
Affected products
- Apple macOS Sequoia before 15.7.8
- Apple macOS Tahoe before 26.6
Timeline
- 2026-07-27: patched: Fixed in macOS Sequoia 15.7.8 and macOS Tahoe 26.6
- 2026-09-14: disclosed: Security advisory published