An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

zetlyn/cve-nvd vulnerability cve CVE-2026-84540 cpe cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* known 2026-09-14

https://nvd.nist.gov/vuln/detail/CVE-2026-84540

Properties

cvss5.5
receipt
Source
NVD
Its words
5.5
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data."
      }
    ],
    "id": "CVE-2026-84540",
    "lastModified": "2026-09-29T17:17:10.617",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-84540",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-16T12:33:40.868624Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:30.393",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
productmacOS
receipt
Source
NVD
Its words
macOS
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
2026-09-29 17:49 UTCmacOS
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data."
      }
    ],
    "id": "CVE-2026-84540",
    "lastModified": "2026-09-29T17:17:10.617",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-84540",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-16T12:33:40.868624Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:30.393",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
statusModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
2026-09-29 17:49 UTCModified
2026-09-29 09:45 UTCAnalyzed
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data."
      }
    ],
    "id": "CVE-2026-84540",
    "lastModified": "2026-09-29T17:17:10.617",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-84540",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-16T12:33:40.868624Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:30.393",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
vendorApple
receipt
Source
NVD
Its words
Apple
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
2026-09-29 17:49 UTCApple
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data."
      }
    ],
    "id": "CVE-2026-84540",
    "lastModified": "2026-09-29T17:17:10.617",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-84540",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-16T12:33:40.868624Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:30.393",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}

Text

An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.