CVE Vulnerabilities

CVE-2026-20607

Improper Privilege Management

Published: Mar 25, 2026 | Modified: Mar 26, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access protected user data.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
MacosApple14.0 (including)14.8.5 (excluding)
MacosApple15.0 (including)15.7.5 (excluding)
MacosApple26.0 (including)26.4 (excluding)

Potential Mitigations

References