Junglewise Threat Intelligence

CVE-2026-86910: Apple macOS APFS permissions issue via path validation bypass

CVE-2026-86910 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

APFS (Apple File System) is the filesystem used across Apple's macOS operating system. A permissions vulnerability allows applications to access restricted files on the system by bypassing path validation checks, potentially exposing sensitive user data or system files that should be protected. This issue affects multiple recent versions of macOS and requires patches to restore proper file access restrictions.

Technical details

This vulnerability is a permissions issue in the APFS filesystem component where path validation logic fails to properly restrict file access. The root cause involves insufficient validation of file paths, allowing a local application with limited privileges to circumvent access controls and read restricted files. The attack vector is local and requires an application to be running on the affected system; no network access or user interaction is needed beyond running a malicious app. An attacker can leverage this flaw to access sensitive files that should be protected by filesystem permissions. Patches are available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate 27 and earlier
  • Apple macOS Sequoia 15.8 and earlier
  • Apple macOS Tahoe 26.7 and earlier

Timeline

  • 2026-09-14: disclosed: CVE-2026-86910 disclosed
  • 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7

References

Related threats