ZeroHour

CVE-2026-65375

mass

macOS Authentication Flaw Lets Apps Trigger Unexpected System Termination

CVSS
EPSS
Published
()
Modified
AI analysis

An authentication weakness in macOS allows an app running on an affected Mac to cause unexpected system termination, effectively a local denial-of-service condition. The flaw is triggered when an app invokes a privileged system operation without the caller being properly authenticated, leading the system to crash or restart rather than rejecting the request. An attacker gains only an availability impact — repeated reboots or crashes of a victim's Mac — with no indication of code execution or data exposure. Affected users are those on macOS versions prior to the fixes, which shipped in macOS Sequoia 15.8, macOS Tahoe 26.6, and macOS Golden Gate 27 as part of a record-setting Apple patch batch. No public proof-of-concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is presumed limited or absent.

What to do: Update to macOS Sequoia 15.8, macOS Tahoe 26.6, or macOS Golden Gate 27 as appropriate for your hardware, since the fix strengthens the authentication check that prevents apps from terminating the system. Restrict app installations to trusted, notarized sources such as the App Store, and enable Gatekeeper to reduce the chance of running a malicious app that could abuse this. Check logs for unexpected shutdowns or kernel panics that may indicate past abuse of this behavior.

Affected
Apple macOS Sequoiaversions prior to 15.8 (fixed in 15.8)
Apple macOS Tahoeversions prior to 26.6 (fixed in 26.6)
Apple macOS Golden Gateversions prior to 27 (fixed in 27)
Estimated exposure
masson the order of 100M+ Macs (Apple's active Mac installed base) — Apple's publicly disclosed installed base includes well over 100 million active Macs, most of which run the macOS lines covered by these fixes; the practically vulnerable subset is those not yet updated to the patched releases.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The issue was addressed with improved authentication. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

In the news

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

Apple's record patch cycle fixes 260+ CVEs across iOS 27 and macOS 27, including CUPS remote code execution, with no active exploitation reported.

Apple patched more than 260 CVEs across its operating systems and software, its largest single patch cycle ever, with iOS 27 fixing 122 flaws and macOS 27 Golden Gate fixing 204. Notable bugs include CVE-2026-43692, a CUPS validation issue allowing remote code execution, and CVE-2026-43689, an iOS privilege-escalation flaw granting root access. Ten CVEs were credited to AI-assisted bug hunting, including CVE-2026-65410 and CVE-2026-65409 found by Calif with Claude and Anthropic Research. None of the vulnerabilities are listed as actively exploited.