Junglewise Threat Intelligence

CVE-2026-84601: Apple macOS permissions bypass in Apple Intelligence

CVE-2026-84601 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

Apple Intelligence is a system feature that processes user requests and data locally on macOS devices. A permissions issue allowed applications to bypass security prompts that normally protect Apple Intelligence features, potentially enabling unauthorized access to sensitive processing capabilities. The vulnerability has been patched in macOS Golden Gate 27.

Technical details

A permissions issue in macOS Apple Intelligence allowed malicious or compromised applications to circumvent security prompts that normally gate access to Apple Intelligence features. The vulnerability was rooted in improper state management in the permissions framework. An attacker with local code execution (user-level access) could trigger the vulnerability without user interaction, as the security prompts could be bypassed. The fix improves state management to properly enforce permission checks. Apple patched this issue in macOS Golden Gate 27, released September 14, 2026.

Affected products

  • Apple macOS Golden Gate prior to 27

Timeline

  • 2026-09-14: patched: Fixed in macOS Golden Gate 27
  • 2026-09-14: disclosed

References

Related threats