Executive brief
A security vulnerability in macOS could allow an individual with physical access to a locked computer to view sensitive user information. This issue affects several versions of the Mac operating system, including Sequoia, Sonoma, and Tahoe. Apple has released software updates to address this flaw by improving security checks on locked devices.
Technical details
A vulnerability classified as CWE-522 (Insufficiently Protected Credentials) exists in macOS Sequoia, Sonoma, and Tahoe. The flaw is rooted in insufficient security checks that fail to properly restrict access to sensitive data when the device is in a locked state. An attacker with physical proximity to the machine can exploit this to bypass intended access controls and view sensitive user information without requiring the user's password. Apple addressed the issue in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.5 by implementing improved validation checks.
Affected products
- Apple macOS Sequoia before 15.7.8
- Apple macOS Sonoma before 14.8.8
- Apple macOS Tahoe before 26.5
Timeline
- 2026-05-11: disclosed: Initial disclosure by Apple
- 2026-05-11: patched: Fixes released in macOS 15.7.8, 14.8.8, and 26.5