Junglewise Threat Intelligence

CVE-2026-84540: Apple macOS authorization bypass in Accounts

CVE-2026-84540 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

macOS manages user access permissions through its Accounts framework. A flaw in state management allows malicious applications to bypass Privacy preferences, potentially gaining unauthorized access to sensitive user data or account features without explicit user consent.

Technical details

An authorization issue exists in the Accounts framework of macOS due to improper state management. A malicious application can exploit this flaw to bypass Privacy preferences and gain access to sensitive user data or perform actions that should require explicit user permission. The vulnerability is local in nature, requiring an attacker to have an application running on the target system. The fix involves improved state management to properly validate authorization checks before granting access to protected resources. This issue affects macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate 27
  • Apple macOS Sequoia 15.8
  • Apple macOS Tahoe 26.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7

References

Related threats