AppleCVE-2026-86894
Apple macOS: protection mechanism failure
High7.5CVE-2026-86894 · Published Sep 14, 2026 · updated Sep 16, 2026
A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out of its sandbox.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| macOS Product | < 27 | 27 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-693
More Apple advisories
All Apple| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 14 | Apple macOS: path traversal | Medium5.5 | 14.8.8+1 more |
| Sep 14 | Apple iOS and iPadOS: out-of-bounds read | Medium5.5 | 27+2 more |
| Sep 14 | A privacy issue was addressed with improved state management | High7.5 | 26.7+2 more |
| Sep 14 | Apple iOS and iPadOS: improper access control | Medium5.5 | 27+2 more |
| Sep 14 | Apple macOS: protection mechanism failure | Medium4.4 | 27 |
| Sep 14 | Apple macOS: path traversal | Medium5.5 | 15.8+2 more |