CVE-2026-64701
massLocal Privilege Escalation to Root in Apple macOS Sequoia and Tahoe
Apple macOS contains an improper permission handling flaw (CWE-280) that allows a malicious app running on an affected Mac to gain root privileges. Exploitation is local: the attacker must already have a malicious application on the target system (CVSS 7.8, AV:L/PR:L/UI:N), so it is typically chained with malware delivery, but no additional user interaction is required once the app is present. Successful exploitation grants full root access, meaning complete compromise of confidentiality, integrity, and availability on the host. Affected systems are macOS Sequoia before 15.7.8 and macOS Tahoe before 26.6, with fixes shipped in those releases. No public proof-of-concept exists and the flaw is not in CISA's KEV, so exploitation is currently none known.
What to do: Update to macOS Sequoia 15.7.8 or macOS Tahoe 26.6 as soon as possible. Because exploitation requires a malicious app already on the Mac, enforce Gatekeeper and notarization and restrict software installation to trusted sources. Treat any malware found on unpatched Macs as potentially having root access — after patching, verify integrity rather than assuming the infection was contained.
| Apple macOS Sequoia | prior to 15.7.8 |
| Apple macOS Tahoe | prior to 26.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
- Vendors
- apple
- Products
- macos
- Weakness
- CWE-280
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.