Junglewise Threat Intelligence

CVE-2026-20623: Apple macOS Foundation permissions issue in user data access

CVE-2026-20623 · Severity: medium · CVSS 5.5 · Published 2026-02-11

Technologies: Apple macOS. Vendors: Apple.

Executive brief

The Foundation framework in macOS contains a permissions vulnerability that allows malicious applications to access protected user data. An attacker would need to deploy a malicious app that exploits this flaw to gain unauthorized access to sensitive information, potentially compromising user privacy and confidential data stored on affected systems.

Technical details

CVE-2026-20623 is a permissions issue in the Foundation framework affecting macOS Sequoia and Tahoe. The vulnerability was addressed by removing the vulnerable code rather than patching it, indicating a logic or access control flaw in how the framework manages protected user data access. The attack requires local execution context (a malicious app must be installed and run on the system). An attacker can bypass permission controls to access protected user data that should be restricted by the operating system's permission model. Patches are available in macOS Sequoia 15.7.4 and macOS Tahoe 26.3, both released February 11, 2026.

Affected products

  • Apple macOS Sequoia before 15.7.4
  • Apple macOS Tahoe before 26.3

Timeline

  • 2026-02-11: disclosed: CVE-2026-20623 disclosed via Apple security advisory
  • 2026-02-11: patched: Fixed in macOS Sequoia 15.7.4 and macOS Tahoe 26.3

References

Related threats