Executive brief
APFS (Apple File System) is the filesystem used across Apple's macOS operating system. A permissions vulnerability allows applications to access restricted files on the system by bypassing path validation checks, potentially exposing sensitive user data or system files that should be protected. This issue affects multiple recent versions of macOS and requires patches to restore proper file access restrictions.
Technical details
This vulnerability is a permissions issue in the APFS filesystem component where path validation logic fails to properly restrict file access. The root cause involves insufficient validation of file paths, allowing a local application with limited privileges to circumvent access controls and read restricted files. The attack vector is local and requires an application to be running on the affected system; no network access or user interaction is needed beyond running a malicious app. An attacker can leverage this flaw to access sensitive files that should be protected by filesystem permissions. Patches are available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Affected products
- Apple macOS Golden Gate 27 and earlier
- Apple macOS Sequoia 15.8 and earlier
- Apple macOS Tahoe 26.7 and earlier
Timeline
- 2026-09-14: disclosed: CVE-2026-86910 disclosed
- 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7