CVE-2026-39874
Undergoing Analysis Undergoing Analysis - In Progress

Permissions Issue in macOS Allows Root Privilege Escalation

Vulnerability report for CVE-2026-39874, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-29

Assigner: Apple Inc.

Description

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-29
Generated
2026-08-17
AI Q&A
2026-07-28
EPSS Evaluated
2026-08-15
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
apple macos From 14.0 (inc) to 14.8.8 (exc)
apple macos From 15.0 (inc) to 15.7.8 (exc)
apple macos From 26.0 (inc) to 26.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-276 During installation, installed file permissions are set to allow anyone to modify those files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a permissions issue that allows a malicious app to gain root privileges. It was addressed by adding additional restrictions in specific macOS versions.

Detection Guidance

This vulnerability involves a permissions issue allowing root privilege escalation. Detection requires checking macOS version against patched releases (Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.6). No specific commands are provided in the context to detect active exploitation.

Impact Analysis

A malicious app exploiting this could gain full control over your system, allowing unauthorized access to sensitive data, installation of malware, or system modifications.

Compliance Impact

The vulnerability allows a malicious app to gain root privileges, which could lead to unauthorized access to sensitive data. This may impact compliance with GDPR (data protection) and HIPAA (health data privacy) by enabling data breaches or unauthorized processing.

Mitigation Strategies

Update to the latest patched versions of macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, or macOS Tahoe 26.6 to address the permissions issue and prevent root privilege escalation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-39874. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart