Time-of-check Time-of-use (TOCTOU) Race Condition in Defender for Endpoint for macOS - CVE-2026-50658
Published: July 17, 2026
Vulnerability identifier: #VU138269
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-50658
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint for Mac, which leads to security restrictions bypass and privilege escalation.
Affected software
Defender for Endpoint for macOS
How to mitigate CVE-2026-50658
Install updates from vendor's website.
Defender for Endpoint for macOS - update to 101.26042.0020