Executive brief
A security vulnerability in macOS Sequoia could allow a malicious application to bypass system launch protections. If exploited, this could enable the application to execute unauthorized code with elevated system privileges. This poses a risk to the integrity of the operating system and the security of user data.
Technical details
A vulnerability exists in the AppleMobileFileIntegrity (AMFI) component of macOS Sequoia. The flaw stems from insufficient checks within launch constraint protections, which are designed to restrict how and when processes are executed. A local malicious application can exploit this issue to bypass these security constraints, leading to arbitrary code execution with elevated privileges. Apple addressed the issue in macOS Sequoia 15.4 by implementing improved validation checks.
Affected products
- Apple macOS Sequoia Before 15.4
Timeline
- 2025-03-31: patched: Fixed in macOS Sequoia 15.4
- 2026-06-10: advisory: Detailed entry added to Apple security advisory
- 2026-06-11: disclosed: NVD publication date