Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-28899

CVE-2026-28899: Apple macOS Gatekeeper Auth Bypass Vulnerability

CVE-2026-28899 is an authentication bypass vulnerability in Apple macOS that allows applications to circumvent Gatekeeper security checks. This post explains the technical details, affected versions, and remediation steps.

Published:

CVE-2026-28899 Overview

CVE-2026-28899 is a logic flaw in Apple macOS that allows an application to bypass Gatekeeper checks. Gatekeeper is the macOS security mechanism that verifies code signatures and notarization status before allowing downloaded applications to execute. Apple addressed the issue with improved checks in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6, and macOS Tahoe 26.7. The vulnerability is categorized under [CWE-693] Protection Mechanism Failure. Exploitation requires local access and user interaction, and successful abuse impacts integrity by permitting execution of code that would normally be blocked.

Critical Impact

An application can bypass Gatekeeper verification on macOS, enabling execution of unsigned or unnotarized code that would otherwise be blocked by system policy.

Affected Products

  • Apple macOS versions prior to Sequoia 15.8
  • Apple macOS Tahoe versions prior to 26.6 and 26.7
  • Apple macOS Golden Gate versions prior to 27

Discovery Timeline

  • 2026-09-14 - CVE-2026-28899 published to the National Vulnerability Database
  • 2026-09-17 - Last updated in NVD database

Technical Details for CVE-2026-28899

Vulnerability Analysis

CVE-2026-28899 stems from a logic issue in the Gatekeeper enforcement path on macOS. Gatekeeper is designed to verify that applications originate from an identified developer and, where applicable, are notarized by Apple before execution. A logic flaw in the verification workflow allowed an application to bypass these checks. According to Apple's advisories, the issue was resolved with improved checks in the affected macOS branches.

The vulnerability is a local-vector integrity issue requiring user interaction. In practical terms, a user opening a crafted application could allow that application to run without the expected Gatekeeper prompts or restrictions. This class of flaw ([CWE-693] Protection Mechanism Failure) is significant because it undermines a foundational macOS trust boundary that many downstream defenses assume is intact.

Root Cause

The root cause is a logic error in the Gatekeeper check sequence. The specific control flow that determines whether an application should be evaluated, quarantined, or blocked contained a condition that could be manipulated to skip enforcement. Apple has not published implementation-level detail beyond noting that the issue was addressed with improved checks.

Attack Vector

Exploitation requires local delivery of a crafted application and user action to launch it. An attacker who can convince a user to open a malicious bundle, such as via a downloaded archive, removable media, or a supply-chain compromise, can achieve execution without Gatekeeper intervention. The vulnerability does not enable remote code execution on its own but removes a key barrier that prevents unsigned or unnotarized payloads from running.

No public exploit code, proof-of-concept, or CISA Known Exploited Vulnerabilities listing is associated with CVE-2026-28899 at the time of publication. Refer to the Apple Support advisories for vendor-provided technical details.

Detection Methods for CVE-2026-28899

Indicators of Compromise

  • Applications executing from user-writable locations such as ~/Downloads or /tmp without a corresponding Gatekeeper prompt or quarantine attribute.
  • Processes spawned from bundles that lack a valid com.apple.quarantine extended attribute despite having been downloaded from a browser or messaging client.
  • Unexpected child processes launched by newly installed applications shortly after first execution.

Detection Strategies

  • Inspect files for the presence and state of the com.apple.quarantine extended attribute using xattr -p com.apple.quarantine <file>.
  • Correlate application first-launch events with the absence of Gatekeeper assessment log entries in the Unified Log (log show --predicate 'subsystem == "com.apple.syspolicy"').
  • Alert on execution of unsigned or ad-hoc signed binaries from user directories using endpoint telemetry.

Monitoring Recommendations

  • Ingest macOS Endpoint Security Framework (ESF) events, particularly ES_EVENT_TYPE_NOTIFY_EXEC and code signing events, into a centralized log platform for retrospective analysis.
  • Monitor syspolicyd and Gatekeeper subsystem logs for anomalies, gaps, or unexpected policy decisions.
  • Track macOS version distribution across the fleet to identify hosts running versions prior to Sequoia 15.8, Tahoe 26.6, Tahoe 26.7, or Golden Gate 27.

How to Mitigate CVE-2026-28899

Immediate Actions Required

  • Update affected systems to macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7, or macOS Golden Gate 27 as appropriate for the hardware.
  • Prioritize patching endpoints used by users who routinely download software from the internet or handle untrusted archives.
  • Audit recently installed applications on unpatched systems for missing quarantine attributes or invalid signatures.

Patch Information

Apple released fixes across four macOS branches. Consult the vendor advisories for build numbers and deployment guidance: Apple Support Article #128067, Apple Support Article #149035, Apple Support Article #149042, and Apple Support Article #149043.

Workarounds

  • Restrict application installation to Mobile Device Management (MDM) approved sources and enforce allow-listing where feasible.
  • Educate users to avoid opening applications from untrusted sources, especially those delivered via disk images or archives from email or messaging platforms.
  • Verify code signatures manually with codesign --verify --deep --strict <app> and spctl --assess --verbose <app> before executing new applications on unpatched systems.
bash
# Verify Gatekeeper assessment and signature status for an application
spctl --assess --verbose=4 /Applications/Example.app
codesign --verify --deep --strict --verbose=2 /Applications/Example.app
xattr -p com.apple.quarantine /Applications/Example.app

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.