DIRAS TAKE
High urgency: working exploit code is publicly available, so prioritize updates to the fixed releases (14.8.8, 15.7.8, 26.6) or isolate machines until you can patch.
What is CVE-2026-39875?
A local attacker can escalate privileges on macOS to root by exploiting a permissions weakness; CVE-2026-39875 allows a malicious app or process with limited privileges to gain full system control without user interaction. Affected releases are macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6. Exploitation requires local access and a low-privilege process; no user click is needed.
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple macOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 14.x | before 14.8.8 | 14.8.8 |
| 15.x | before 15.7.8 | 15.7.8 |
| 26.x | before 26.6 | 26.6 |
Is CVE-2026-39875 being exploited?
Public exploit code is available.
How to fix CVE-2026-39875
- Install the vendor updates: upgrade to macOS Sonoma 14.8.8, Sequoia 15.7.8, or Tahoe 26.6 as appropriate.
- Block untrusted local installs and restrict which users can install or run third-party software.
- Monitor endpoints for suspicious local privilege escalation activity and unexpected root processes.
- Apply vendor guidance and hardening for limiting local attack surface until systems are patched.
Frequently asked questions
Is CVE-2026-39875 being actively exploited?
Public exploit code is available for CVE-2026-39875, indicating attackers can reproduce the issue; there is public proof-of-concept code but no CISA Known Exploited Vulnerabilities listing.
Which macOS versions are affected by CVE-2026-39875?
macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6 are affected.
Is there a patch for CVE-2026-39875?
Yes. Apple fixed the issue in macOS Sonoma 14.8.8, Sequoia 15.7.8, and Tahoe 26.6; apply the appropriate update for your systems.
Does CVE-2026-39875 require authentication?
No separate authentication is required beyond local access; a low-privilege local process or malicious app can exploit the permissions flaw to gain root.
References
- nvd.nist.gov/vuln/detail/CVE-2026-39875
- cve.org/CVERecord?id=CVE-2026-39875
- support.apple.com/en-us/128067
- support.apple.com/en-us/128071
- support.apple.com/en-us/128072
- All Apple CVEs on CVE Radar
- CVEs published in September 2026