Junglewise Threat Intelligence

CVE-2026-20672: Apple macOS information disclosure via privacy control bypass

CVE-2026-20672 · Severity: info · Published 2026-07-27

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A vulnerability in macOS could allow a malicious application to bypass privacy controls and access sensitive user data. This affects users running older versions of macOS Sequoia and Sonoma. Updating to the latest software versions prevents unauthorized apps from harvesting private information.

Technical details

An information disclosure vulnerability exists in macOS Sequoia and Sonoma due to insufficient privacy controls. A locally installed malicious application could exploit this flaw to bypass permission requirements and access sensitive user data. Apple addressed the issue by improving privacy enforcement mechanisms. The vulnerability is fixed in macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8.

Affected products

  • Apple macOS Sequoia Before 15.7.8
  • Apple macOS Sonoma Before 14.8.8

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats