Executive brief
LaunchServices is a system component in macOS responsible for application launching and file type associations. A permissions vulnerability allows apps to bypass intended access controls and read protected user data without proper authorization. Apple has addressed this issue in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26.3.
Technical details
This is a permissions validation issue in Apple's LaunchServices framework. The vulnerability stems from insufficient restrictions on which data protected apps can access; the flaw was remediated by adding additional permission checks. An unprivileged app can exploit this to access sensitive user data that should be protected by macOS security policies. Attack preconditions include having a malicious app installed on the target system. Apple has addressed the issue by implementing additional access control restrictions in the patched versions.
Affected products
- Apple macOS Sequoia before 15.7.4
- Apple macOS Sonoma before 14.8.4
- Apple macOS Tahoe before 26.3
Timeline
- 2026-02-11: disclosed
- 2026-02-11: patched: Fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26.3