---
id: CVE-2026-84585
title: A permissions issue was addressed with improved state management
summary: >-
  A permissions issue was addressed with improved state management. This issue
  is fixed in macOS Golden Gate 27. An app may be able to access local network
  devices without user consent.
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-284
vendor: apple
product: macos
affected:
  - macos < 27.0
patched:
  - macos 27.0
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T15:27:08.020'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84585'
references:
  - url: 'https://support.apple.com/en-us/149035'
    label: product-security@apple.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T14:58:55.303997Z'
epss: 0.00157
epssPercentile: 0.04073
ingestedAt: '2026-09-14T21:15:17.535Z'
---

## Overview

A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access local network devices without user consent.

## Affected

- `macos < 27.0`

## Remediation

Upgrade past the affected range:

- `macos 27.0`
