CVE-2026-86917
massApple macOS App Privilege Escalation to Root (Sequoia, Tahoe, Golden Gate)
CVE-2026-86917 is a local privilege escalation flaw in Apple macOS stemming from improper handling of permissions (CWE-280), addressed by Apple with additional restrictions. An app already running on an affected Mac as a normal user can bypass the intended permission checks and gain root privileges, with no user interaction required once the app is executing (CVSS 3.1: 7.8, AV:L/AC:L/PR:L/UI:N). Successful exploitation gives the app full root access with high impact on confidentiality, integrity, and availability, making this a classic building block for malware persistence and full-device takeover after initial access (e.g., a malicious or compromised downloaded app). Affected software includes macOS Sequoia prior to 15.8, macOS Tahoe prior to 26.7, and macOS Golden Gate prior to 27, which were all patched by Apple. No public proof of concept is known, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been confirmed.
What to do: Update affected Macs to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) as soon as possible, and enable automatic security updates across the fleet. Because exploitation requires a malicious or compromised app to already be running, enforce Gatekeeper and notarization checks, restrict installation of untrusted software, and treat any unexplained app gaining root as a high-severity incident. On managed deployments, verify patch compliance and prioritize Macs that allow sideloading of third-party apps.
| Apple macOS Sequoia | before 15.8 |
| Apple macOS Tahoe | before 26.7 |
| Apple macOS Golden Gate | before 27 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
- Vendors
- apple
- Products
- macos
- Weakness
- CWE-280
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.