DIRAS TAKE
Urgently install Apple’s updates: the vendor published fixes for the affected branches (15.8, 26.7, 27), so patching is the fastest way to remove the risk.
What is CVE-2026-65381?
An attacker who can run a malicious app on macOS may break out of the app sandbox and execute code outside its restrictions. CVE-2026-65381 is a validation problem in entitlement checking that can allow a sandbox escape. Affects macOS Sequoia 15.x before 15.8, Tahoe 26.x before 26.7, and Golden Gate 27.x before 27; an attacker needs to run a specially crafted app on the target system.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of Apple macOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 15.x | before 15.8 | 15.8 |
| 26.x | before 26.7 | 26.7 |
| 27.x | before 27 | 27 |
Is CVE-2026-65381 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-65381
- Install the vendor fixes: update to macOS Sequoia 15.8, Tahoe 26.7, or Golden Gate 27 as appropriate.
- Block or restrict execution of untrusted apps via Gatekeeper, MDM policies, or application whitelisting.
- Monitor endpoints for unknown or suspicious local applications and unusual post‑execution activity.
- Follow Apple’s security guidance and apply OS updates promptly across affected devices.
Frequently asked questions
Is CVE-2026-65381 being actively exploited?
There are no public reports of exploitation as of 2026-09-29.
Which macOS versions are affected by CVE-2026-65381?
The issue affects macOS Sequoia 15.x before 15.8, Tahoe 26.x before 26.7, and Golden Gate 27.x before 27.
Is there a patch for CVE-2026-65381?
Yes. Apple released fixes in macOS Sequoia 15.8, Tahoe 26.7, and Golden Gate 27.
Does CVE-2026-65381 require authentication?
Exploitation requires a malicious app to run on the target macOS device; it does not require a network login but does require execution of the crafted app.
References
- nvd.nist.gov/vuln/detail/CVE-2026-65381
- cve.org/CVERecord?id=CVE-2026-65381
- support.apple.com/en-us/149035
- support.apple.com/en-us/149042
- support.apple.com/en-us/149043
- All Apple CVEs on CVE Radar
- CVEs published in September 2026