Executive brief
Apple's macOS operating system contains a permissions validation flaw in the App Transport Security (ATS) framework that allows apps to access sensitive user data they should not have permission to read. An attacker with control of a malicious app could exploit this to steal protected information like authentication tokens, location data, or other confidential user details stored on the system.
Technical details
CVE-2026-65342 is a permissions validation issue in the App Transport Security (ATS) component of macOS. The vulnerability allows a local application to bypass sandbox restrictions and access sensitive user data that should be protected by ATS rules. The root cause is insufficient validation of app permissions when accessing protected resources. An attacker can craft a malicious app that, when run locally, exploits this permissions check failure to read confidential files or data. The issue has been patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 through improved validation logic.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed: Security advisory published
- 2026-09-14: patched: Patches released in macOS Golden Gate 27, Sequoia 15.8, and Tahoe 26.7