AI for Security Summit: Join Figma, Perplexity & Wiz. [Register]

CVE-2026-86917
macOS vulnerability analysis and mitigation

Overview

CVE-2026-86917 is a privilege escalation vulnerability in the macOS Kernel component caused by improper handling of permissions. A local application with standard user privileges may be able to gain root privileges due to insufficient restrictions. The vulnerability affects macOS Sequoia versions prior to 15.8, macOS Tahoe versions prior to 26.7, and macOS Golden Gate versions prior to 27. It was disclosed and patched on September 14, 2026, and carries a CVSS v3.1 base score of 7.8 (High) (Apple Advisory - Sequoia, Apple Advisory - Tahoe, Apple Advisory - Golden Gate, Github Advisory).

Technical details

The vulnerability is classified as CWE-280 (Improper Handling of Insufficient Permissions or Privileges), meaning the macOS Kernel does not correctly handle scenarios where a process has insufficient privileges, potentially allowing it to follow unexpected code paths that elevate its access level. Apple addressed the issue by adding additional restrictions to the permissions handling logic in the Kernel component. The attack vector is local, requires low privileges, and no user interaction, making it straightforward for a malicious app already running on the system to exploit. The researcher credited with discovery is Hiroki Imai of LAC Co., Ltd. (Apple Advisory - Sequoia, Apple Advisory - Tahoe, Github Advisory).

Impact

Successful exploitation allows a local application running with standard (non-root) user privileges to escalate to root, achieving full control over the affected macOS system. With root access, an attacker could read or modify all system files, install persistent malware, disable security controls such as SIP (System Integrity Protection), and access sensitive user data. The confidentiality, integrity, and availability impacts are all rated High, reflecting the total compromise potential of the affected system (Github Advisory, Apple Advisory - Tahoe).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Github Advisory). The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, further reducing immediate risk (Apple Advisory - Sequoia).

Mitigation and workarounds

Apple has released patches addressing this vulnerability in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, all released on September 14, 2026. Users and administrators should update their macOS systems to the latest available version for their respective product line immediately. No configuration-based workarounds have been published by Apple; updating to a patched version is the only recommended remediation (Apple Advisory - Sequoia, Apple Advisory - Tahoe, Apple Advisory - Golden Gate).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86917HIGH7.8
  • macOS logomacOS
  • Kernel
NoYesSep 14, 2026
CVE-2026-86924NONEN/A
  • macOS logomacOS
  • MobileAccessoryUpdater
NoYesSep 14, 2026
CVE-2026-86910NONEN/A
  • macOS logomacOS
  • APFS
NoYesSep 14, 2026
CVE-2026-86902NONEN/A
  • macOS logomacOS
  • NSDocument
NoYesSep 14, 2026
CVE-2026-86891NONEN/A
  • macOS logomacOS
  • Core Bluetooth
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management