ZeroHour

CVE-2026-28937

mass

App-Mediated Sensitive Data Access Flaw in Apple macOS (Fixed in macOS Golden Gate 27)

CVSS 3.1
5.5 medium
EPSS
Published
()
Modified
AI analysis

CVE-2026-28937 is a state-management flaw in Apple macOS that can allow an app running on a Mac to access sensitive user data that it should not be permitted to read. The issue is triggered locally: an attacker would need to get a malicious app onto the victim's machine, or abuse an already-installed app, rather than attacking the system remotely over a network. Successful abuse results in unauthorized access to sensitive user information — a privacy/information-disclosure impact — not remote code execution. The flaw affects Macs running macOS versions prior to the fix; Apple addressed it through improved state management and shipped the patch in macOS Golden Gate 27 as part of a broad September software update. CVSS has not yet been scored, no public proof-of-concept is known, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Update to macOS Golden Gate 27 or later via System Settings > General > Software Update as soon as possible, and have IT admins expedite deployment across managed Mac fleets. Because the flaw is app-mediated, review and restrict permissions granted to third-party apps and avoid installing untrusted software. No configuration workaround is documented, so patching is the primary mitigation.

Affected
Apple macOSAll versions prior to macOS Golden Gate 27 (Apple did not enumerate specific affected version ranges)
Estimated exposure
masson the order of 100 million+ Mac users, shrinking as users adopt macOS Golden Gate 27 — Apple's active Mac installed base is publicly estimated at well over 100 million devices, nearly all of which run macOS builds that predate the Golden Gate 27 fix unless updated.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

This issue was addressed through improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.

Weakness
CWE-284
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.