Junglewise Threat Intelligence

CVE-2026-65383: Apple macOS Gatekeeper bypass

CVE-2026-65383 · Severity: medium · CVSS 4.4 · Published 2026-09-14

Technologies: Apple macOS, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

macOS Gatekeeper is Apple's security mechanism that validates whether applications are safe to run before launching them. A vulnerability allows a malicious application to bypass these checks, potentially enabling users to unknowingly run untrusted or compromised software. This undermines a key protection mechanism in macOS and could lead to malware installation or unauthorized access to system resources.

Technical details

The vulnerability is a Gatekeeper bypass in macOS that allows an app to circumvent code-signing and notarization checks. The root cause involves inadequate validation logic in the Gatekeeper security framework. The attack requires local execution and user action to run a maliciously crafted application. An attacker can craft an app that bypasses Gatekeeper checks, potentially allowing installation of unsigned or unnotarized code. The vulnerability is fixed in macOS Golden Gate 27, released on September 14, 2026.

Affected products

  • Apple macOS Golden Gate prior to 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in macOS Golden Gate 27

References

Related threats