Junglewise Threat Intelligence

CVE-2025-46307: Apple macOS Tahoe logic issue allows sensitive data access

CVE-2025-46307 · Severity: info · CVSS 4.3 · Published 2026-05-26

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A security vulnerability in macOS Tahoe could allow a malicious application to access sensitive user information. This occurs due to a logic error in how the operating system restricts data access for installed apps. Users should update to macOS Tahoe 26 to ensure their private data remains protected from unauthorized application access.

Technical details

A logic vulnerability exists in macOS Tahoe prior to version 26 that allows an application to bypass intended data access restrictions. The issue stems from insufficient enforcement of permissions, which Apple addressed by implementing improved restrictions within the operating system's logic. An attacker would need to convince a user to install and run a malicious application on the local system to exploit this flaw. Successful exploitation results in the unauthorized retrieval of sensitive user data. The vulnerability is resolved in macOS Tahoe 26.

Affected products

  • Apple macOS Tahoe before 26

Timeline

  • 2025-09-15: patched: macOS Tahoe 26 released
  • 2026-05-26: disclosed: CVE published

References

Related threats