Executive brief
A path handling vulnerability in macOS allows applications to gain elevated privileges on affected systems. An attacker could exploit this flaw to escalate their access rights and perform unauthorized actions. This issue affects multiple macOS versions including Golden Gate, Sequoia, and Tahoe.
Technical details
CVE-2026-64790 is a path handling issue that was addressed with improved validation. The vulnerability allows applications to bypass normal permission restrictions through improper path validation, potentially leading to privilege escalation. The attack requires local application execution on an affected system. The issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 or later.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched