Junglewise Threat Intelligence

CVE-2026-84541: Apple macOS input validation issue in file access

CVE-2026-84541 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

macOS is the operating system used by Mac computers. A flaw in how the system validates user input could allow an application to access files that should be restricted from it. This could expose sensitive user data or documents without requiring any special privileges or user interaction beyond running the affected app.

Technical details

The vulnerability is an input validation issue affecting APFS (Apple File System) path validation. The root cause involves insufficient validation of paths when checking file access permissions, allowing a local application to bypass intended access controls. The attack requires a malicious application to be installed and executed on the affected system. An attacker can use this to read or access files outside the intended scope of restrictions. The issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 with improved path validation.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats