Executive brief
A race condition in macOS allows an app to cause unexpected system crashes by bypassing additional validation checks. This can interrupt business operations and user workflows on affected Mac computers. The vulnerability was patched in macOS Golden Gate 27, Sequoia 15.8, and Tahoe 26.7.
Technical details
A race condition exists in an unspecified Apple macOS component that lacks sufficient validation during concurrent operations. The vulnerability allows a local unprivileged application to trigger a denial-of-service condition by exploiting timing windows in resource access. The attack requires no user interaction and can be executed by any installed app. Apple addressed this issue by adding additional validation logic to prevent the race condition. Patches are available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 released on September 14, 2026.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed: Security advisory published; patches released in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7