ZeroHour

CVE-2026-84631

mass

macOS App Root Privilege Escalation via Missing Entitlement Checks (Golden Gate 27)

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-84631 is a local privilege escalation flaw in macOS (CWE-280, improper handling of special values) caused by missing entitlement checks that can let a regular unprivileged application gain root privileges. Exploitation requires an attacker to already be able to run an app on the target Mac (low privileges required, no user interaction), after which that app can fully compromise the machine with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.8, High). Apple fixed the issue by adding additional entitlement checks in macOS Golden Gate 27; the exact range of earlier affected macOS versions was not disclosed. Any Mac still running a macOS version prior to this fix is potentially exposed, since the vulnerability is in the operating system itself rather than a specific optional component. No public proof of concept is known, the flaw is not on CISA's KEV list, and there are no reports of exploitation in the wild.

What to do: Update affected Macs to macOS Golden Gate 27 (or the latest macOS release supported by the hardware) as soon as it is available. Until patched, enforce Gatekeeper settings that limit app installation to the App Store and notarized/identified developers, since exploitation requires a malicious or compromised app to run locally. Watch endpoint logs/EDR for applications unexpectedly acquiring elevated (root) privileges.

Affected
Apple macOS
Estimated exposure
mass≈100,000,000+ active Macs potentially affected before patching — The flaw resides in the macOS operating system, so every un-patched Mac is in scope, and Apple's publicly disclosed device figures put the active Mac install base at over 100 million units.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to gain root privileges.

Vendors
apple
Products
macos
Weakness
CWE-280
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.