Executive brief
Apple's AppKit framework manages graphical user interface elements on macOS systems. A permissions flaw allows installed applications to access protected user data that should be restricted, potentially exposing sensitive information like contacts, documents, or personal settings without proper user consent.
Technical details
CVE-2026-84587 is a permissions issue in Apple's AppKit framework affecting macOS systems with Apple silicon. The vulnerability allows a local application to bypass access restrictions and read protected user data through improved validation mechanisms. The issue requires a malicious or compromised application to be installed and executed on the target system. An attacker can exploit this to exfiltrate sensitive user information without triggering privacy prompts or obtaining explicit user consent. The flaw was fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 released on September 14, 2026.
Affected products
- Apple macOS Golden Gate 27 and later
- Apple macOS Sequoia 15.8 and later
- Apple macOS Tahoe 26.7 and later
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched