Executive brief
A vulnerability in Apple's operating systems could allow a malicious application to access sensitive user data. This occurs due to a timing issue in how the system handles file-related services. If exploited, an attacker could bypass privacy protections to view information they should not have access to. Apple has released updates for iPhones, iPads, Macs, and other devices to resolve this issue.
Technical details
A race condition exists within the FileProvider framework across multiple Apple operating systems. The vulnerability stems from insufficient validation during concurrent operations, which can be exploited by a local malicious application to bypass intended data access restrictions. Successful exploitation allows the app to read sensitive user information. Apple addressed the root cause by implementing additional validation logic and improved state management. The fix is available in iOS 26.5, iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, and corresponding versions of tvOS, visionOS, and watchOS.
Affected products
- Apple iOS Before 26.5
- Apple iPadOS Before 26.5
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple visionOS Before 26.5
- Apple watchOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory