Executive brief
A vulnerability in macOS could allow a malicious application to access a user's Contacts without their permission. This occurs due to a timing issue in how the system handles file shortcuts, potentially bypassing standard privacy protections. If exploited, an unauthorized app could harvest personal contact information, compromising user privacy.
Technical details
A race condition exists in macOS within the handling of symbolic links. By exploiting this timing window, a local application can bypass privacy consent requirements to access the Contacts database. The vulnerability was addressed by improving the handling of symbolic links and adding additional validation. The issue affects macOS Sequoia, Sonoma, and Tahoe, and is resolved in versions 15.7.7, 14.8.7, and 26.5 respectively.
Affected products
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory