Executive brief
A security vulnerability in macOS Tahoe could allow a malicious application to bypass standard security boundaries and access a user's sensitive personal data. This issue affects the system's sandbox, which is designed to keep apps isolated from private information. Apple has released an update to strengthen these protections and prevent unauthorized data access.
Technical details
A vulnerability in macOS Tahoe (prior to version 26.1) allowed a malicious application to bypass sandbox restrictions to access sensitive user data. The issue was classified as an access control vulnerability where the sandbox did not sufficiently restrict certain operations. Apple addressed this by implementing additional sandbox restrictions and improved checks. An attacker would need to convince a user to install and run a malicious application on the local system to exploit this flaw. The fix is included in macOS Tahoe 26.1.
Affected products
- Apple macOS Tahoe Before 26.1
Timeline
- 2025-11-03: patched: Fixed in macOS Tahoe 26.1
- 2026-06-11: disclosed: NVD publication date