Junglewise Threat Intelligence

CVE-2026-84618: Apple macOS permissions issue in multiple frameworks

CVE-2026-84618 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Multiple Apple macOS system frameworks contain a permissions validation vulnerability that allows apps to access sensitive user data without proper authorization. An attacker who creates a malicious app could exploit this to read private user information including account identifiers and authentication details. The issue affects macOS versions prior to Golden Gate 27, Sequoia 15.8, and Tahoe 26.7, with patches now available.

Technical details

This vulnerability is a permissions validation flaw across multiple macOS frameworks (Accessibility, AppKit, Apple Account, App Store, ATS, AuthKit, and others) that fails to properly enforce access controls. The root cause stems from inadequate validation during permission checks, allowing a local application to bypass sandbox restrictions and access sensitive user data. The attack requires no special privileges but does require an app to be installed and executed on the system. An attacker can read restricted account identifiers, authentication tokens, and user data that should be protected. Fixes are available in macOS Golden Gate 27, Sequoia 15.8, and Tahoe 26.7 with improved validation and additional access restrictions applied across affected frameworks.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7

References

Related threats