Executive brief
A logic flaw in macOS could allow a malicious application to bypass security restrictions and access sensitive user information. This affects users of macOS Sequoia, Sonoma, and Tahoe. If exploited, this could lead to the unauthorized disclosure of private data stored on the computer.
Technical details
A logic issue existed in macOS Sequoia, Sonoma, and Tahoe that could allow an application to access user-sensitive data without proper authorization. The vulnerability was caused by insufficient validation within a system component. Apple addressed this by implementing improved validation logic. An attacker would need to have an application running on the target system to exploit this flaw. Patches are available in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Affected products
- Apple macOS Sequoia before 15.7.8
- Apple macOS Sonoma before 14.8.8
- Apple macOS Tahoe before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched