Junglewise Threat Intelligence

CVE-2026-64712: Apple macOS privilege escalation via autofs

CVE-2026-64712 · Severity: high · CVSS 7.8 · Published 2026-09-14

Technologies: Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

macOS is Apple's operating system used on Mac computers. A vulnerability in the autofs component allows an attacker with control of a network directory server to execute arbitrary code with root privileges, potentially compromising all data and system integrity on affected machines.

Technical details

CVE-2026-64712 is a path traversal vulnerability in the macOS autofs subsystem that allows arbitrary code execution with root privileges. The vulnerability exists in the autofs component's handling of network directory server responses. An attacker who controls or can intercept communications with a network directory server (NIS, NFS, or LDAP) can inject malicious paths that bypass validation, leading to execution of arbitrary code with root-level privileges. The vulnerability requires the attacker to have network-level access or control of a directory server; local user interaction is not required. Patches are available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7

References

Related threats