Executive brief
macOS is Apple's desktop operating system that handles user accounts, app permissions, and data protection. CVE-2026-84556 is an authorization flaw that allows apps to access sensitive user data without proper permission checks. This could enable unauthorized access to private information if an attacker compromises or creates a malicious application.
Technical details
CVE-2026-84556 is an authorization issue in macOS that allows unauthorized access to sensitive user data. The vulnerability is rooted in insufficient access control enforcement, likely in a core system framework or service responsible for data protection and permission verification. The attack requires local execution or app-level privileges; a malicious or compromised application can bypass authorization checks to read protected user data. Apple addressed this flaw by implementing improved access control logic in the affected component. Patches are available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7
- 2026-09-14: disclosed: CVE-2026-84556 published on NVD