Executive brief
A vulnerability in Apple's CoreMedia framework could allow a malicious application to access a user's private information. CoreMedia is a core component of macOS that handles multimedia data like audio and video. If exploited, this could lead to the unauthorized exposure of sensitive personal data stored on the device.
Technical details
An information disclosure vulnerability exists in the CoreMedia framework of macOS Sequoia, Sonoma, and Tahoe. The flaw is rooted in improper state management within the component. A local malicious application can exploit this issue to bypass intended access controls and read private information. Apple has addressed the vulnerability by improving state management logic in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5.
Affected products
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched