Junglewise Threat Intelligence

CVE-2025-30459: Apple macOS Sequoia privacy issue in sensitive data access

CVE-2025-30459 · Severity: info · Published 2026-06-11

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A privacy vulnerability in macOS Sequoia could allow a malicious application installed on a computer to access sensitive user data. This issue was resolved by removing the problematic code in the macOS 15.4 update. Users should update their systems to prevent unauthorized apps from harvesting private information.

Technical details

A privacy vulnerability existed in macOS Sequoia where an application could bypass intended data protections to access sensitive user information. The root cause was identified as vulnerable code within the operating system's privacy framework. Apple addressed this by removing the affected code entirely. Exploitation requires a malicious application to be running on the target system. The fix is included in macOS Sequoia 15.4.

Affected products

  • Apple macOS Sequoia Before 15.4

Timeline

  • 2025-03-31: patched: macOS Sequoia 15.4 released
  • 2026-06-11: advisory: CVE published/updated in NVD

References

Related threats