CVE-2026-39871

HIGH

macOS - Information Disclosure

Title source: manual
STIX 2.1

Description

A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to observe unprotected user data.

Scores

CVSS v3 7.5
EPSS 0.0004
EPSS Percentile 12.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-552
Status published
Products (4)
Apple/macOS < 14.8.7
Apple/macOS < 15.7.7
Apple/macOS < 26.5
apple/macos 14.0 - 14.8.7
Published May 11, 2026
Tracked Since May 12, 2026