Junglewise Threat Intelligence

CVE-2026-84577: Apple macOS sandbox bypass via access restrictions

CVE-2026-84577 · Severity: high · CVSS 8.2 · Published 2026-09-14

Technologies: Apple macOS, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

macOS is Apple's operating system for Mac computers, protected by sandbox technology that isolates apps to prevent unauthorized access to system resources and user data. CVE-2026-84577 allows an app to bypass these sandbox restrictions, potentially gaining access to sensitive files and data that should be protected. This issue affects multiple recent macOS versions and has been patched in macOS Golden Gate 27 and macOS Tahoe 26.7.

Technical details

CVE-2026-84577 is a sandbox bypass vulnerability in macOS that allows applications to circumvent access restrictions designed to isolate apps from sensitive system resources. The vulnerability was addressed through additional sandbox restrictions and improved validation logic. The issue is exploitable by any locally installed app without requiring special user interaction or elevated privileges beyond standard app execution. An attacker can exploit this to access protected user data, system files, and potentially escalate capabilities beyond the app's intended entitlements. Patches are available in macOS Golden Gate 27 (released September 14, 2026) and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Patched in macOS Golden Gate 27 and macOS Tahoe 26.7

References

Related threats