Executive brief
A vulnerability in macOS Sequoia could allow a malicious application to bypass security restrictions and access sensitive user data. This occurs due to a flaw in how the operating system processes directory paths. Users should update to macOS Sequoia 15.4 to protect their private information from unauthorized access by third-party apps.
Technical details
A path validation vulnerability exists in macOS Sequoia's handling of directory paths. The flaw stems from a parsing issue that could be exploited by a malicious application to bypass filesystem permissions or sandbox restrictions, potentially leading to unauthorized access to sensitive user data. Apple addressed this issue in macOS Sequoia 15.4 by implementing more robust path validation logic. While the specific component within macOS was not named in the brief advisory, the fix involves improved sanitization of directory strings to prevent path traversal or similar logic errors.
Affected products
- Apple macOS Sequoia Before 15.4
Timeline
- 2025-03-31: patched: macOS Sequoia 15.4 released
- 2026-06-11: disclosed: CVE published