CVE-2026-64701

7.8

Apple · macOS

A permissions issue in Apple macOS allows a malicious local application to escalate privileges to root, potentially compromising the entire operating system.

Executive summary

A high severity privilege escalation vulnerability in Apple macOS allows a local malicious application to gain full root access to the system.

Vulnerability

This is a permissions-based vulnerability where a local attacker with low privileges can exploit a restriction failure to execute code with root-level privileges on the host system.

Business impact

The ability for a malicious application to achieve root privileges represents a total compromise of the affected workstation or server. An attacker gaining root access can bypass all security controls, exfiltrate sensitive data, install persistent backdoors, or disable security software. Given the CVSS score of 7.8, this flaw poses a significant risk to organizational confidentiality, integrity, and availability.

Remediation

Immediate Action: Update all affected macOS systems to version 15.7.8 (Sequoia) or 26.6 (Tahoe) immediately to apply the necessary permission restrictions.

Proactive Monitoring: Monitor system logs for unexpected privilege escalation events, the creation of new root-level user accounts, or unauthorized modifications to sensitive system files.

Compensating Controls: Implement strict application allowlisting policies to prevent unauthorized or untrusted binaries from executing on macOS endpoints.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Due to the severity of local privilege escalation, all administrators should prioritize the deployment of the provided macOS security updates. Ensuring that all endpoints are running the latest patched version is the only definitive way to prevent malicious applications from gaining unauthorized root access to your infrastructure.

More Apple CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources