Junglewise Threat Intelligence

CVE-2024-40858: Apple macOS Sequoia Improper Access Control in Contacts

CVE-2024-40858 · Severity: high · CVSS 7.1 · Published 2026-04-02

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A security flaw in macOS could allow a malicious application to access a user's Contacts without their permission. This bypasses standard privacy protections designed to keep personal information private. If exploited, an attacker could harvest contact details, including names, phone numbers, and email addresses, without the user ever seeing a consent prompt.

Technical details

A permissions issue (CWE-284) was identified in macOS Sequoia where additional restrictions were required to properly enforce privacy boundaries. The vulnerability allows a locally installed application to bypass Transparency, Consent, and Control (TCC) prompts to access the Contacts database. An attacker with local user privileges could programmatically exfiltrate contact information without triggering the standard system authorization dialogs. Apple addressed this issue in macOS Sequoia 15.1 by implementing more stringent permission checks and restrictions.

Affected products

  • Apple macOS Sequoia Before 15.1

Timeline

  • 2024-10-24: patched: Fixed in macOS Sequoia 15.1
  • 2026-04-02: disclosed: NVD publication date

References

Related threats