Executive brief
macOS manages system permissions to control which apps can access local network devices without user approval. A permissions flaw in the state management allowed apps to bypass this protection and access local network devices without user consent. This could allow a malicious application installed on a system to discover and communicate with printers, smart home devices, and other networked equipment on the user's home or office network without any warning or permission dialog.
Technical details
This is a permissions bypass vulnerability in macOS's local network access control mechanism. The root cause is a state management issue in the permission-checking framework that allows applications to circumvent the user consent requirement for accessing local network devices. An attacker would need to have a malicious application installed on the target system (requires local code execution). The vulnerability allows the app to access local network devices (such as printers, smart home devices, and networked services) without triggering the permission prompt that normally alerts users. The vulnerability is fixed in macOS Golden Gate 27, released September 14, 2026.
Affected products
- Apple macOS Golden Gate before 27
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixed in macOS Golden Gate 27