Executive brief
A security vulnerability in macOS could allow a malicious application to bypass user privacy settings. This means an app might access sensitive information or perform actions that the user has specifically restricted in their system preferences. Apple has released updates for macOS Sequoia, Sonoma, and Tahoe to address this issue.
Technical details
An authorization vulnerability exists in macOS due to improper state management. A local malicious application can exploit this flaw to bypass Privacy preferences (TCC), potentially gaining unauthorized access to protected user data or system resources. The issue was resolved by improving how the system manages authorization states. Affected versions include macOS Sequoia before 15.7.8, macOS Sonoma before 14.8.8, and macOS Tahoe before 26.6. Exploitation requires a malicious application to be executed on the target system.
Affected products
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Sonoma Before 14.8.8
- Apple macOS Tahoe Before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched