Executive brief
macOS includes a Privacy framework that controls which apps can access sensitive user data and settings. A permissions vulnerability allowed malicious apps to modify user Privacy preferences without proper authorization, potentially enabling unauthorized access to location, camera, microphone, and other sensitive features. This issue affects multiple Mac models and has been patched in macOS Golden Gate 27.
Technical details
A permissions validation issue in the macOS Privacy framework allowed installed applications to modify user privacy preferences without proper authorization checks. The vulnerability required local code execution (an installed app) but no user interaction beyond the app being present on the system. An attacker could exploit this to disable privacy protections (e.g., microphone or camera restrictions), enabling unauthorized access to sensitive user data and device hardware. The issue was addressed with additional permission restrictions in macOS Golden Gate 27 released on September 14, 2026.
Affected products
- Apple macOS Golden Gate prior to 27
Timeline
- 2026-09-14: patched: Fixed in macOS Golden Gate 27