ZeroHour

CVE-2026-65362

mass

macOS Improper Access Control Flaw Lets Apps Escalate to Root

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

Apple macOS contains an improper access control flaw (CWE-284) that allows a malicious app running on an affected Mac to elevate itself to root privileges. The flaw is triggered locally, with no user interaction required beyond the app already being executed on the machine. A successful exploit gives the attacker full system control, including the ability to read, modify, or delete any data, install persistent malware, and bypass macOS security protections. The issue affects macOS Sequoia before 15.8, macOS Tahoe before 26.7, and macOS Golden Gate before 27, and was addressed with improved checks in each of those releases. There is no known public proof-of-concept, no evidence of in-the-wild exploitation, and the vulnerability is not on CISA's KEV list as of this writing.

What to do: Update affected Macs to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) as soon as possible. Because exploitation requires a malicious app to already be running on the Mac, keep Gatekeeper restricted to App Store and identified/notarized developers and review recently installed or sideloaded apps. After patching, check for unexpected root-owned processes, LaunchDaemons, or unauthorized admin accounts that could indicate prior escalation.

Affected
Apple macOS Sequoiaprior to 15.8 (fixed in 15.8)
Apple macOS Tahoeprior to 26.7 (fixed in 26.7)
Apple macOS Golden Gateprior to 27 (fixed in 27)
Estimated exposure
mass≈100 million+ Macs potentially affected (order of magnitude: 10^8 devices) — Based on Apple's publicly reported active Mac installed base of roughly 100 million+ devices, the large majority of which run currently-supported macOS releases such as Sequoia and Tahoe covered by these fixes.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

Vendors
apple
Products
macos
Weakness
CWE-284
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.