Executive brief
Gatekeeper is the security mechanism that prevents users from accidentally running malicious or unauthorized applications on macOS. A logic flaw allows a malicious application to bypass these checks, potentially enabling attackers to distribute and execute unauthorized software without triggering security warnings. This affects multiple recent versions of macOS across Intel and Apple silicon machines.
Technical details
A logic issue in the autofs component of macOS allows an application to bypass Gatekeeper verification checks. The vulnerability exists in the state management of Gatekeeper's decision logic. The issue is addressed with improved checks in the autofs subsystem. An attacker would need to craft a malicious application; local execution or user interaction to run the app is required. Patches are available in macOS Golden Gate 27 (CVE-2026-84570), macOS Sequoia 15.8, and macOS Tahoe 26.7.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched