ZeroHour

CVE-2026-64712

mass

Local Privilege Escalation to Root in macOS Sequoia, Tahoe, and Golden Gate

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

An improper access control flaw (CWE-284) in macOS allows an application running on an affected Mac to gain root privileges, meaning full compromise of the system's confidentiality, integrity, and availability. The flaw is triggered by a locally running app abusing insufficient checks in an OS component — no user interaction is needed, and the attacker only needs code already executing on the machine. All Macs running macOS Sequoia prior to 15.8, macOS Tahoe prior to 26.7, and macOS Golden Gate prior to 27 are affected. Apple addressed the issue with improved checks in macOS Sequoia 15.8, macOS Tahoe 26.7, and macOS Golden Gate 27. No public proof-of-concept exists and there is no known exploitation in the wild.

What to do: Update to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 as soon as possible. Because exploitation requires malicious code already running on the Mac, restrict software installation to trusted sources (App Store or notarized apps) and review recently installed or sideloaded third-party applications for signs of misuse.

Affected
Apple macOS Sequoiaprior to 15.8
Apple macOS Tahoeprior to 26.7
Apple macOS Golden Gateprior to 27
Estimated exposure
masstens of millions to ~100M+ Macs (essentially all unpatched macOS installs) — macOS holds roughly 15% of desktop OS market share with an active installed base exceeding 100 million Macs, and every device not yet on the patched releases is affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

Vendors
apple
Products
macos
Weakness
CWE-284
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.