PT-2026-39777 · Apple · Macos Tahoe+1
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
macOS Tahoe versions prior to 26.4
Description
A flaw in the macOS Archive Utility allows a malicious application to access arbitrary files due to insufficient permissions checking. The issue can be exploited if a user executes an attacker-controlled shell script and is tricked into performing a drag-and-drop action. This process allows an attacker to swap a signed application's executable on disk, bypassing code signing protections that typically guard applications downloaded from the App Store or directly from the web.
Recommendations
Update macOS Tahoe to version 26.4.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos
Macos Tahoe