Executive brief
A vulnerability in macOS could allow a malicious application to access unprotected user data. This issue stems from how the operating system handles file paths, potentially exposing sensitive information to unauthorized apps. Users should update to the latest versions of macOS Sequoia, Sonoma, or Tahoe to protect their personal information.
Technical details
A path handling vulnerability exists in macOS Sequoia, Sonoma, and Tahoe. The issue is caused by flawed logic in how the operating system processes file paths, which could be exploited by a local application to bypass intended data protections and observe sensitive user information. Apple addressed this vulnerability by improving the path handling logic. The fix is available in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5. An attacker would need to have the ability to run an application on the target system to exploit this flaw.
Affected products
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory