Junglewise Threat Intelligence

CVE-2026-65401: Apple macOS race condition privilege escalation in kernel

CVE-2026-65401 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

Apple macOS Golden Gate and Tahoe contain a race condition in kernel component handling that can allow a malicious app to execute arbitrary code with elevated privileges or cause unexpected system crashes. This vulnerability affects multiple macOS versions and could allow attackers to bypass system security or cause service disruptions.

Technical details

A race condition vulnerability was identified in Apple's kernel state handling, affecting the macOS Golden Gate and Tahoe operating systems. The vulnerability class is a race condition in state management, likely within a kernel-level component responsible for privilege or resource management. The attack vector is local, requiring an app to be installed and executed on the affected system. An attacker can exploit this race condition to cause unexpected system termination or, in certain contexts, potentially elevate privileges. The issue was addressed with improved state handling and synchronization mechanisms. The vulnerability is patched in macOS Golden Gate 27 and macOS Tahoe 26.7, released on September 14, 2026.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in macOS Golden Gate 27 and macOS Tahoe 26.7

References

Related threats