Executive brief
A security issue in Apple macOS and watchOS could allow a malicious application to bypass authorization checks. This could result in the unauthorized access of sensitive user data stored on the device. Users should update to the latest software versions to ensure improved state management protections are in place.
Technical details
An authorization vulnerability exists in multiple Apple operating systems, including macOS (Sequoia, Sonoma, Tahoe) and watchOS. The flaw stems from improper state management during authorization checks. A locally installed malicious application could exploit this weakness to bypass intended restrictions and access sensitive user information. Apple has addressed this issue by improving how the system manages authorization states. The fix is available in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, and watchOS 26.6.
Affected products
- Apple macOS Sequoia before 15.7.8
- Apple macOS Sonoma before 14.8.8
- Apple macOS Tahoe before 26.6
- Apple watchOS before 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: disclosed
- 2026-07-27: patched