Executive brief
A logic flaw in macOS CoreServices—a critical system component that handles file operations and app integration—allows unauthorized access to sensitive user data. An app can exploit this validation bypass to read private information without proper authorization.
Technical details
A logic issue in CoreServices' validation routine permits unauthorized data access. The vulnerability is addressed through improved validation checks in the affected component. Attack requires a malicious app capable of interacting with CoreServices; no special network access or user interaction is required. An exploiting app can access sensitive user data that should be protected by OS sandboxing and permission controls. Fixes are available in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26.2.
Affected products
- Apple macOS Sequoia before 15.7.4
- Apple macOS Sonoma before 14.8.4
- Apple macOS Tahoe before 26.2
Timeline
- 2025-12-17: disclosed
- 2025-12-12: patched: Fixed in macOS Tahoe 26.2
- 2026-02-11: patched: Fixed in macOS Sequoia 15.7.4