ZeroHour

CVE-2026-65393

mass

macOS Permission Validation Flaw Lets Apps Access User-Sensitive Data

CVSS 3.1
5.5 medium
EPSS
Published
()
Modified
AI analysis

CVE-2026-65393 is a permissions/validation weakness in Apple's macOS (and related tooling in Xcode) in which an app running on an affected system may be able to access user-sensitive data that it should not be permitted to read. Exploitation requires a malicious or compromised application to already be present and executing on the victim's Mac, where it abuses the insufficient permission validation rather than a remotely reachable network flaw. A successful abuser gains access to sensitive user data (for example, data protected by macOS privacy controls), but there is no indication of arbitrary code execution or remote compromise. The issue affects users running macOS versions prior to macOS Golden Gate 27, as well as developers on Xcode versions prior to Xcode 27, since fixes shipped in both releases as part of a large Apple security update. There is no known public proof-of-concept, no confirmed in-the-wild exploitation, and the CVE is not in the CISA KEV catalog.

What to do: Update to macOS Golden Gate 27 as soon as practical, and developers should move to Xcode 27 so apps are built against the corrected validation behavior. In the interim, audit installed applications and the permissions granted under System Settings > Privacy & Security, revoking unusual data-access grants and removing untrusted apps, since exploitation depends on a malicious app already running locally. Monitor Apple's security advisory and threat feeds, as this flaw was patched alongside a very large batch of fixes that attackers may prioritize for reverse engineering.

Affected
Apple macOS Golden Gateversions prior to macOS Golden Gate 27 (fixed in macOS Golden Gate 27)
Apple Xcodeversions prior to Xcode 27 (fixed in Xcode 27)
Estimated exposure
mass≈100M+ users (Apple's active Mac installed base is well over 100 million devices) — Nearly all actively used Macs not yet upgraded to macOS Golden Gate 27 are theoretically exposed, based on Apple's publicly stated active Mac installed base exceeding 100 million devices; real-world risk is moderated by the requirement for…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An app may be able to access user-sensitive data.

Weakness
CWE-863
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple's coordinated rollout patches 273 unique vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS and Safari, including remote code execution flaws.

Apple shipped one of its largest coordinated security updates on September 14, 2026, fixing 273 unique CVEs across iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27 and Xcode 27. Highlights include CVE-2026-65414, a Bluetooth out-of-bounds write enabling remote code execution, and CVE-2026-84607, an AVEVideoEncoder race condition granting kernel privileges to sandboxed apps. macOS Golden Gate 27 covers the broadest set with 210 CVEs, and Apple states none of the flaws were exploited in the wild.