CVE-2026-65362
massmacOS Improper Access Control Flaw Lets Apps Escalate to Root
Apple macOS contains an improper access control flaw (CWE-284) that allows a malicious app running on an affected Mac to elevate itself to root privileges. The flaw is triggered locally, with no user interaction required beyond the app already being executed on the machine. A successful exploit gives the attacker full system control, including the ability to read, modify, or delete any data, install persistent malware, and bypass macOS security protections. The issue affects macOS Sequoia before 15.8, macOS Tahoe before 26.7, and macOS Golden Gate before 27, and was addressed with improved checks in each of those releases. There is no known public proof-of-concept, no evidence of in-the-wild exploitation, and the vulnerability is not on CISA's KEV list as of this writing.
What to do: Update affected Macs to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) as soon as possible. Because exploitation requires a malicious app to already be running on the Mac, keep Gatekeeper restricted to App Store and identified/notarized developers and review recently installed or sideloaded apps. After patching, check for unexpected root-owned processes, LaunchDaemons, or unauthorized admin accounts that could indicate prior escalation.
| Apple macOS Sequoia | prior to 15.8 (fixed in 15.8) |
| Apple macOS Tahoe | prior to 26.7 (fixed in 26.7) |
| Apple macOS Golden Gate | prior to 27 (fixed in 27) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
- Vendors
- apple
- Products
- macos
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.