Junglewise Threat Intelligence

CVE-2026-65378: Apple macOS authorization bypass in Accounts

CVE-2026-65378 · Severity: high · CVSS 7.5 · Published 2026-09-14

Technologies: Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

macOS's Accounts framework handles user authentication and privacy settings across Apple's operating system. A flaw in the Accounts component allows an app to bypass authorization checks and access sensitive user data or settings without proper permission. An attacker could exploit this to leak credentials, access personal information, or elevate privileges.

Technical details

The vulnerability is an authorization bypass in macOS Accounts component caused by improper state management. The issue allows a locally-installed malicious app to circumvent authorization controls and access restricted user data or settings. The attack requires the app to be installed on the target system but does not require authentication or user interaction beyond installation. An attacker can leverage this to read private user information or modify account settings. The vulnerability is patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate 27
  • Apple macOS Sequoia 15.8
  • Apple macOS Tahoe 26.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats