A critical vulnerability, identified as CVE-2026-39118, allows users to disable security tools on Apple’s macOS, including the CrowdStrike Falcon Sensor. The issue stems from a fundamental macOS design flaw that Apple reportedly refuses to patch. This decision leaves third-party software vendors like CrowdStrike responsible for developing their own mitigations.
CrowdStrike has acknowledged the flaw and awarded a bug bounty to researchers at XM Cyber. The company is currently developing internal fixes to address the security gap. While no evidence of widespread exploitation exists, full technical details will be presented at the Black Hat USA 2026 conference.