Junglewise Threat Intelligence

CVE-2026-84555: Apple macOS authorization bypass allowing sensitive user data access

CVE-2026-84555 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Sequoia. Vendors: Apple.

Executive brief

An authorization flaw in Apple's macOS allows applications to access sensitive user data without proper permission controls. The vulnerability affects the core access control mechanisms in macOS Golden Gate 27 and macOS Sequoia 15.8. Successful exploitation could enable an app to bypass privacy protections and expose personal information, though no active exploitation in the wild has been reported.

Technical details

This is an authorization/access control vulnerability where improved access control mechanisms were deployed as a fix. The root cause involves insufficient validation of application permissions when accessing sensitive user data. The attack vector is local and requires a malicious application to be installed and executed on the target system. No special privileges or user interaction beyond app installation is needed. An attacker can craft a malicious app that accesses protected user data by circumventing the authorization checks. The vulnerability is addressed in macOS Golden Gate 27 and macOS Sequoia 15.8, released September 14, 2026.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8

Timeline

  • 2026-09-14: disclosed: CVE-2026-84555 published; patches released for macOS Golden Gate 27 and macOS Sequoia 15.8
  • 2026-09-14: patched: Fixed in macOS Golden Gate 27 and macOS Sequoia 15.8

References

Related threats