Executive brief
A vulnerability in macOS Sequoia could allow a malicious application to modify protected parts of the file system. This bypasses security controls designed to prevent unauthorized changes to critical system files. If exploited, this could lead to system instability, unauthorized data access, or the compromise of the operating system's integrity.
Technical details
An improper access control vulnerability (CWE-284) exists in macOS Sequoia prior to version 15.1. The issue stems from insufficient checks when applications attempt to access or modify restricted areas of the file system. A malicious application installed on the system can exploit this flaw to bypass system integrity protections and modify protected files. Apple addressed this issue in macOS Sequoia 15.1 by implementing improved validation checks. While some sources list a network attack vector, the nature of the flaw (malicious application) typically implies local execution or delivery via user interaction.
Affected products
- Apple macOS Sequoia up to (excluding) 15.1
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory: Apple released security notes for macOS Sequoia 15.1
- 2024-10-24: patched: Approximate release date of macOS 15.1 based on versioning history