Executive brief
A security vulnerability in macOS Tahoe could allow a malicious application to access sensitive user information. This occurs due to a logic error in how the operating system restricts data access for installed apps. Users should update to macOS Tahoe 26 to ensure their private data remains protected from unauthorized application access.
Technical details
A logic vulnerability exists in macOS Tahoe prior to version 26 that allows an application to bypass intended data access restrictions. The issue stems from insufficient enforcement of permissions, which Apple addressed by implementing improved restrictions within the operating system's logic. An attacker would need to convince a user to install and run a malicious application on the local system to exploit this flaw. Successful exploitation results in the unauthorized retrieval of sensitive user data. The vulnerability is resolved in macOS Tahoe 26.
Affected products
- Apple macOS Tahoe before 26
Timeline
- 2025-09-15: patched: macOS Tahoe 26 released
- 2026-05-26: disclosed: CVE published