ZeroHour

CVE-2026-28899

mass

Gatekeeper bypass in Apple macOS Sequoia, Tahoe, and Golden Gate

CVSS
EPSS
Published
()
Modified
AI analysis

CVE-2026-28899 is a logic flaw in Apple's Gatekeeper security mechanism on macOS that allows a malicious app to bypass Gatekeeper's validation checks. Gatekeeper normally verifies that downloaded apps are notarized and signed before allowing them to run; a bypass means an attacker-controlled app downloaded to a victim's Mac could execute without passing those checks or triggering the standard user-approval flow. Successful exploitation gives an attacker a way to launch untrusted code on target machines, which is typically used as an initial-access step that is chained with other flaws to escape sandboxes or gain elevated privileges. All Macs running macOS Sequoia before 15.8, macOS Tahoe before 26.6, and macOS Golden Gate before 27 are affected; Apple addressed the issue with improved checks in its September 14 broad software update. As of the available data, there is no public proof-of-concept, no CVSS score, and no evidence of in-the-wild exploitation.

What to do: Update affected Macs immediately: macOS Sequoia to 15.8, macOS Tahoe to 26.6 or 26.7, or macOS Golden Gate to 27 via System Settings > Software Update. On managed fleets, verify patch compliance and confirm Gatekeeper is enabled (e.g., `spctl --status` reports assessments enabled). Gatekeeper bypasses are commonly chained with browser exploits and sandbox escapes, so treat rapid patching as high priority and monitor Apple's security advisories for follow-on CVEs.

Affected
Apple macOS SequoiaPrior to 15.8 (fixed in 15.8)
Apple macOS TahoePrior to 26.6 (fixed in 26.6 and 26.7)
Apple macOS Golden GatePrior to 27 (fixed in 27)
Estimated exposure
massOrder of 100 million+ Macs (roughly 10^8), shrinking as users patch — Apple's active Mac installed base is publicly estimated at well over 100 million devices, and every Mac on the listed affected OS versions prior to the September 14 fixes is exposed, so the unpatched population plausibly numbers in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may bypass Gatekeeper checks.

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.