macOS 27.x < 27.0 Multiple Vulnerabilities (149035)

critical Nessus Plugin ID 363355

Synopsis

The remote host is missing a macOS update that fixes multiple vulnerabilities

Description

The remote host is running a version of macOS / Mac OS X that is 27.x prior to the full release of 27.0. It is, therefore, affected by multiple vulnerabilities:

- A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious app may be able to break out of its sandbox. (CVE-2026-65381)

- An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. (CVE-2026-65400)

- An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A remote attacker may be able to cause unexpected app termination or arbitrary code execution. (CVE-2026-65414)

Note that Nessus has not tested for these issues but has instead relied only on the operating system's self-reported version number.

Solution

Upgrade to the full release of macOS 27.0 or later.

See Also

https://support.apple.com/en-us/149035

Plugin Details

Severity: Critical

ID: 363355

File Name: macos_149035.nasl

Version: 1.1

Type: Local

Agent: macosx

Published: 10/6/2026

Updated: 10/6/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.4

Percentile: 99.82

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-65400

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:apple:mac_os_x:27.0, cpe:/o:apple:macos:27.0

Patch Publication Date: 9/14/2026

Vulnerability Publication Date: 8/6/2026

CISA Known Exploited Vulnerability Due Dates: 8/21/2026

Reference Information

CVE: CVE-2022-3437, CVE-2026-20683, CVE-2026-28899, CVE-2026-28934, CVE-2026-28937, CVE-2026-28966, CVE-2026-28968, CVE-2026-28969, CVE-2026-34979, CVE-2026-43664, CVE-2026-43677, CVE-2026-43683, CVE-2026-43684, CVE-2026-43686, CVE-2026-43687, CVE-2026-43688, CVE-2026-43689, CVE-2026-43690, CVE-2026-43691, CVE-2026-43692, CVE-2026-43695, CVE-2026-43696, CVE-2026-43697, CVE-2026-43698, CVE-2026-43719, CVE-2026-43737, CVE-2026-43738, CVE-2026-43741, CVE-2026-43785, CVE-2026-43786, CVE-2026-43787, CVE-2026-43788, CVE-2026-43789, CVE-2026-43790, CVE-2026-43791, CVE-2026-64712, CVE-2026-64714, CVE-2026-64718, CVE-2026-64752, CVE-2026-64753, CVE-2026-64756, CVE-2026-64760, CVE-2026-64790, CVE-2026-65342, CVE-2026-65344, CVE-2026-65345, CVE-2026-65348, CVE-2026-65354, CVE-2026-65358, CVE-2026-65359, CVE-2026-65360, CVE-2026-65361, CVE-2026-65362, CVE-2026-65364, CVE-2026-65365, CVE-2026-65369, CVE-2026-65374, CVE-2026-65375, CVE-2026-65376, CVE-2026-65377, CVE-2026-65378, CVE-2026-65380, CVE-2026-65381, CVE-2026-65382, CVE-2026-65383, CVE-2026-65393, CVE-2026-65395, CVE-2026-65398, CVE-2026-65399, CVE-2026-65400, CVE-2026-65401, CVE-2026-65402, CVE-2026-65403, CVE-2026-65404, CVE-2026-65405, CVE-2026-65406, CVE-2026-65407, CVE-2026-65408, CVE-2026-65409, CVE-2026-65410, CVE-2026-65412, CVE-2026-65413, CVE-2026-65414, CVE-2026-65415, CVE-2026-84487, CVE-2026-84489, CVE-2026-84491, CVE-2026-84492, CVE-2026-84497, CVE-2026-84505, CVE-2026-84506, CVE-2026-84507, CVE-2026-84509, CVE-2026-84510, CVE-2026-84511, CVE-2026-84512, CVE-2026-84513, CVE-2026-84514, CVE-2026-84515, CVE-2026-84516, CVE-2026-84517, CVE-2026-84518, CVE-2026-84519, CVE-2026-84520, CVE-2026-84521, CVE-2026-84522, CVE-2026-84523, CVE-2026-84524, CVE-2026-84525, CVE-2026-84526, CVE-2026-84527, CVE-2026-84530, CVE-2026-84531, CVE-2026-84532, CVE-2026-84533, CVE-2026-84534, CVE-2026-84535, CVE-2026-84536, CVE-2026-84537, CVE-2026-84538, CVE-2026-84540, CVE-2026-84541, CVE-2026-84543, CVE-2026-84544, CVE-2026-84546, CVE-2026-84548, CVE-2026-84549, CVE-2026-84550, CVE-2026-84551, CVE-2026-84552, CVE-2026-84553, CVE-2026-84554, CVE-2026-84555, CVE-2026-84556, CVE-2026-84558, CVE-2026-84559, CVE-2026-84560, CVE-2026-84561, CVE-2026-84563, CVE-2026-84564, CVE-2026-84565, CVE-2026-84566, CVE-2026-84567, CVE-2026-84568, CVE-2026-84569, CVE-2026-84570, CVE-2026-84571, CVE-2026-84572, CVE-2026-84573, CVE-2026-84574, CVE-2026-84575, CVE-2026-84576, CVE-2026-84577, CVE-2026-84578, CVE-2026-84580, CVE-2026-84581, CVE-2026-84583, CVE-2026-84584, CVE-2026-84585, CVE-2026-84586, CVE-2026-84587, CVE-2026-84588, CVE-2026-84589, CVE-2026-84596, CVE-2026-84597, CVE-2026-84600, CVE-2026-84601, CVE-2026-84602, CVE-2026-84606, CVE-2026-84607, CVE-2026-84609, CVE-2026-84611, CVE-2026-84612, CVE-2026-84616, CVE-2026-84617, CVE-2026-84618, CVE-2026-84619, CVE-2026-84620, CVE-2026-84621, CVE-2026-84622, CVE-2026-84624, CVE-2026-84625, CVE-2026-84626, CVE-2026-84628, CVE-2026-84630, CVE-2026-84631, CVE-2026-84632, CVE-2026-84635, CVE-2026-86869, CVE-2026-86870, CVE-2026-86876, CVE-2026-86881, CVE-2026-86882, CVE-2026-86884, CVE-2026-86888, CVE-2026-86889, CVE-2026-86891, CVE-2026-86894, CVE-2026-86897, CVE-2026-86898, CVE-2026-86900, CVE-2026-86901, CVE-2026-86902, CVE-2026-86903, CVE-2026-86905, CVE-2026-86909, CVE-2026-86910, CVE-2026-86911, CVE-2026-86917, CVE-2026-86924

APPLE-SA: 149035