CVE-2026-84568

Summary

A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker with control of a network directory server may be able to execute arbitrary code with root privileges.

Affected Software

VendorProductVersion RangeStatus
ApplemacOS0 < 15.8affected
ApplemacOS0 < 26.7affected
ApplemacOS0 < 27affected

Weaknesses

  • An attacker with control of a network directory server may be able to execute arbitrary code with root privileges

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References