Executive brief
macOS includes sandboxing protections that restrict what data applications can access, including sensitive information on the system clipboard (pasteboard). This vulnerability allows an application to bypass those protections and read private user data from the pasteboard, such as passwords, financial information, or other sensitive content the user has copied. The issue is fixed in macOS Golden Gate 27.
Technical details
This is a sandbox escape vulnerability affecting macOS system pasteboard access controls. The root cause is insufficient sandbox restrictions on pasteboard access, allowing applications to read data from the system clipboard that should be protected. Attack vector is local; a malicious app installed on the system can access sensitive user data copied to the pasteboard without requiring user interaction or elevated privileges beyond normal app execution. An attacker can achieve confidentiality impact by harvesting passwords, tokens, financial information, and other sensitive text the user has copied. The fix is available in macOS Golden Gate 27, released 2026-09-14.
Affected products
- Apple macOS prior to Golden Gate 27
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixed in macOS Golden Gate 27