Junglewise Threat Intelligence

CVE-2026-65375: Apple macOS denial-of-service in Accounts framework

CVE-2026-65375 · Severity: high · CVSS 7.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Apple's Accounts framework manages user authentication and credentials across macOS. A flaw in how the system handles authentication state can cause unexpected termination (system crash). An app exploiting this could crash the operating system, disrupting user productivity and potentially corrupting ongoing work.

Technical details

The vulnerability is an authentication state-handling issue in the Accounts framework (CVE-2026-65375). The root cause involves a logic error in state management during authentication operations that leads to unexpected system termination. The attack requires no special privileges or network access—a malicious or compromised application running locally can trigger the condition. The fix involves improved authentication logic and state validation. Patches are available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.6.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.6

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: macOS Golden Gate 27 released

References

Related threats