Executive brief
macOS handles file system operations and directory access control for all applications. A flaw in how the operating system validates directory paths could allow malicious apps to bypass these controls and access sensitive user files and data they are not authorized to read. This could expose personal documents, emails, photos, and other private information.
Technical details
A path parsing issue exists in macOS directory path handling that allows bypassing access controls through path validation flaws. The vulnerability is addressed through improved path validation logic, and does not require user interaction or special privileges—a malicious application running on the system can trigger it directly. An attacker can exploit this to access sensitive user data outside their sandbox or permission scope. The issue is fixed in macOS Sonoma 14.8.8 and macOS Golden Gate 27.
Affected products
- Apple macOS Sonoma 14.8.8 and earlier
- Apple macOS Golden Gate 27 and later (fixed)
Timeline
- 2026-09-14: disclosed
- 2026-07-27: patched: Fixed in macOS Sonoma 14.8.8
- 2026-09-14: patched: Fixed in macOS Golden Gate 27