ZeroHour

CVE-2026-84568

mass

macOS Path Traversal via Malicious Network Directory Server Enables Root Code Execution

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

Apple patched a path traversal flaw (CWE-22) in macOS that is triggered when the system processes data returned by a network directory server, such as an LDAP/Active Directory server a Mac is bound to. An attacker who controls such a directory server can return directory data containing crafted traversal-style paths that escape their intended directories, causing macOS components running as root to write or execute files at attacker-chosen locations. Successful exploitation yields arbitrary code execution with root privileges on the client Mac. In principle all Macs running versions older than the fixed releases are vulnerable, but the realistic attack surface is limited to machines that consult a network directory server — primarily enterprise-managed Macs — because the attacker must first control that server, consistent with the CVSS 3.1 local attack vector and low-privilege prerequisites (7.8, high). The issue is fixed in macOS Sequoia 15.8, macOS Tahoe 26.7, and macOS Golden Gate 27; no public proof of concept or in-the-wild exploitation is known.

What to do: Update to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later), which contain the improved path validation. Until patched, audit and remove any unneeded network directory bindings (via Directory Utility or configuration profiles), restrict trusted directory servers to well-secured infrastructure, and watch directory-bound Macs for unexpected root-owned file writes or unfamiliar root processes. MDM operators should verify fleet-wide installation of the fixed builds and flag machines that cannot update.

Affected
Apple macOS Sequoiaprior to 15.8 (fixed in 15.8)
Apple macOS Tahoeprior to 26.7 (fixed in 26.7)
Apple macOS Golden Gateprior to 27 (fixed in 27)
Estimated exposure
massTens of millions of unpatched Macs overall, with an exploitable subset of roughly 1-5 million directory-bound enterprise Macs (estimate) — Apple's active Mac installed base is well over 100 million devices, and only the fraction enrolled in enterprise environments with LDAP/Active Directory bindings realistically meets the attack prerequisites.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker with control of a network directory server may be able to execute arbitrary code with root privileges.

Vendors
apple
Products
macos
Weakness
CWE-22
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple's coordinated rollout patches 273 unique vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS and Safari, including remote code execution flaws.

Apple shipped one of its largest coordinated security updates on September 14, 2026, fixing 273 unique CVEs across iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27 and Xcode 27. Highlights include CVE-2026-65414, a Bluetooth out-of-bounds write enabling remote code execution, and CVE-2026-84607, an AVEVideoEncoder race condition granting kernel privileges to sandboxed apps. macOS Golden Gate 27 covers the broadest set with 210 CVEs, and Apple states none of the flaws were exploited in the wild.