Junglewise Threat Intelligence

CVE-2024-44286: Apple macOS Sequoia keyboard input bypass on locked device

CVE-2024-44286 · Severity: high · CVSS 7.5 · Published 2026-04-02

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A security issue in macOS Sequoia could allow an individual with physical access to a locked computer to interact with running applications. By inputting keyboard events, an unauthorized person could potentially view or manipulate data within apps that should be protected by the lock screen. This vulnerability has been resolved in macOS Sequoia 15.1.

Technical details

An authentication bypass vulnerability (CWE-288) exists in macOS Sequoia prior to version 15.1. The flaw stems from improved state management issues that fail to properly restrict keyboard input when the device is in a locked state. An attacker with physical access to the machine can send keyboard events to active applications, potentially bypassing the lock screen's intended protections. Apple addressed this issue in macOS Sequoia 15.1 by improving state management logic.

Affected products

  • Apple macOS Sequoia before 15.1

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory
  • 2026-04-02: patched: Fixed in macOS Sequoia 15.1

References

Related threats