Executive brief
A race condition in macOS Golden Gate 27's Accessibility framework allows local applications to bypass security controls and access sensitive user data such as passwords, health information, or financial details. This vulnerability requires that an attacker first trick a user into installing a malicious app, but once installed, the app can steal protected information without explicit user permission.
Technical details
A race condition vulnerability exists in the Accessibility framework due to improper state management during inter-process communication. The vulnerability allows a local application to exploit a timing window where security checks are performed inconsistently, enabling unauthorized access to sensitive user data marked for protection. An attacker must have a malicious app installed on the target system (local attack vector). The vulnerability is addressed in macOS Golden Gate 27 through improved state management that eliminates the race condition window. No evidence of in-the-wild exploitation has been reported.
Affected products
- Apple macOS Golden Gate before 27
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixed in macOS Golden Gate 27