
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20684 is a permissions issue in Apple macOS that allows an app to bypass Gatekeeper security checks. The vulnerability affects macOS Tahoe versions prior to 26.4 and was disclosed and patched on March 24, 2026. It was discovered by Koh M. Nakagawa (@tsunek0h) of FFRI Security, Inc., and is classified as a Security Feature Bypass affecting the AppleScript component. The CVSS v3.1 base score is 3.3 (Low) (Apple Advisory, Feedly).
The vulnerability is rooted in improper access control (CWE-284) within the AppleScript component of macOS Tahoe. A permissions issue in how macOS enforces Gatekeeper restrictions allowed a malicious app to bypass these checks, potentially enabling execution of untrusted or unsigned code. The attack vector is local, requires no special privileges, but does require user interaction — consistent with a social engineering scenario where a user is tricked into running a malicious application. No public proof-of-concept code has been identified (Apple Advisory, Feedly).
Successful exploitation allows an app to bypass macOS Gatekeeper checks, undermining a core macOS security control designed to prevent execution of untrusted or unsigned software. The primary impact is to integrity (low), as an attacker could cause a user to unknowingly run malicious applications that would otherwise be blocked. Confidentiality and availability are not directly impacted by this vulnerability, though a bypassed Gatekeeper could serve as an initial access vector for further compromise (Apple Advisory, Feedly).
com.apple.quarantine extended attribute that were downloaded from the internet, particularly in user-writable directories such as /tmp, ~/Downloads, or ~/Library.Apple has addressed this vulnerability in macOS Tahoe 26.4, released March 24, 2026. Users running macOS Tahoe versions prior to 26.4 should update immediately via System Settings > General > Software Update. No official workaround has been provided for systems that cannot be updated. As a general precaution, users should avoid opening applications from unverified or untrusted sources (Apple Advisory).
The vulnerability was part of a broader Apple security update for macOS Tahoe 26.4 that addressed over 140 vulnerabilities across Apple platforms, which received coverage from security news outlets and community aggregators. The SANS Internet Storm Center noted the release in their diary, and CIS published an advisory regarding multiple vulnerabilities in Apple products patched in this update. No specific high-profile researcher commentary or significant social media discussion focused exclusively on CVE-2026-20684 has been identified (SANS ISC, CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."