Executive brief
A security flaw in macOS could allow a malicious application to access a user's sensitive personal data. This issue affects the CoreServices component, which handles fundamental system functions. If exploited, an attacker could bypass standard security protections to steal private information stored on the computer.
Technical details
A logic vulnerability exists in the CoreServices component of macOS. The flaw stems from insufficient validation within the component's logic, which can be exploited by a malicious application running on the system. Successful exploitation allows the application to bypass intended access controls to retrieve sensitive user information. Apple addressed the issue by implementing improved validation routines. The fix is available in macOS Sequoia 15.7, macOS Sonoma 14.8, and macOS Tahoe 26.
Affected products
- Apple macOS Sequoia Before 15.7
- Apple macOS Sonoma Before 14.8
- Apple macOS Tahoe Before 26
Timeline
- 2025-09-15: patched: Initial release of patches for Sequoia, Sonoma, and Tahoe.
- 2026-05-26: disclosed: Advisory published/updated with CVE details.