CVE-2026-86889

Summary

A certificate validation issue was addressed with improved certificate validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to intercept network traffic.

Affected Software

VendorProductVersion RangeStatus
ApplemacOS0 < 15.8affected
ApplemacOS0 < 26.7affected
ApplemacOS0 < 27affected

Weaknesses

  • An attacker in a privileged network position may be able to intercept network traffic

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References