Junglewise Threat Intelligence

CVE-2026-86911: Apple macOS clickjacking protection bypass in secure prompts

CVE-2026-86911 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Executive brief

macOS includes security prompts to protect users when applications attempt sensitive operations. A malicious app can bypass clickjacking protections that prevent these prompts from being tricked, allowing it to perform restricted actions without proper user authorization.

Technical details

This vulnerability is a clickjacking/state management issue in macOS secure prompts. A malicious application can bypass existing clickjacking protections by exploiting a state management flaw, allowing it to interact with or suppress security prompts that normally require explicit user interaction. The attack requires a malicious app to be installed and executing on the system (local attack vector). An attacker can achieve unauthorized access to sensitive operations that should be protected by user confirmation prompts. The issue is fixed in macOS Golden Gate 27 through improved state management.

Affected products

  • Apple macOS Golden Gate prior to 27

Timeline

  • 2026-09-14: patched: Fixed in macOS Golden Gate 27
  • 2026-09-14: disclosed

References

Related threats