Junglewise Threat Intelligence

CVE-2026-65361: Apple macOS Accessibility data protection issue

CVE-2026-65361 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

macOS includes an Accessibility framework that helps users with assistive needs interact with their computers. A flaw in this component allows malicious applications to access sensitive user data that should be protected. An attacker could exploit this by distributing a trojanized app that harvests private information without user knowledge or consent.

Technical details

This is a data protection vulnerability in the macOS Accessibility framework (CVE-2026-43664) where an application can access sensitive user data due to insufficient access controls. The vulnerability is triggered locally by a malicious or compromised app; no network access or elevated privileges are required, though the app must first be installed on the system. An attacker can read protected user information that should be restricted even within the sandboxed app environment. Apple addressed this issue by improving data protection mechanisms in the Accessibility framework. Patches are available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: patched
  • 2026-09-14: disclosed

References

Related threats