Executive brief
macOS is Apple's operating system for Mac computers. A malicious application can bypass file access restrictions and read files that should be protected from unauthorized access. This could allow attackers to steal sensitive user data, configuration files, or other restricted content stored on the system.
Technical details
A permissions validation flaw exists in the APFS (Apple File System) component of macOS, where path validation is insufficient to enforce file access restrictions. The vulnerability allows a malicious or compromised application running locally to access files outside its intended sandbox boundaries. The attack requires the malicious application to already be installed and running on the system; no network interaction is required. An attacker can read arbitrary restricted files, potentially including system configuration, user credentials, or private data. Apple addressed this in macOS Golden Gate 27, Sequoia 15.8, and Tahoe 26.7 with improved path validation.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed: CVE-2026-84559 publicly disclosed
- 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7