Executive brief
Gatekeeper is macOS's security feature that verifies whether downloaded applications are safe to run before opening them. A logic issue in the autofs component allows applications to bypass these security checks, potentially enabling malicious software to run without proper verification. This could allow attackers to distribute trojanized applications that would normally be blocked by system protections.
Technical details
CVE-2026-84570 is a logic issue in the macOS autofs component that allows applications to bypass Gatekeeper security checks. The vulnerability stems from insufficient validation in the autofs logic, addressed by implementing improved checks. Exploitation requires local execution capability but does not appear to require elevated privileges or user interaction beyond application installation. An attacker can craft a malicious application that evades Gatekeeper verification, bypassing a critical macOS security boundary. Patches are available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, all released on September 14, 2026.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched