Executive brief
An authorization vulnerability in macOS and watchOS could allow a malicious application to bypass security controls and access sensitive user data. This issue stems from how the operating system manages internal states when granting permissions. If exploited, a user's private information could be exposed to unauthorized apps installed on the device.
Technical details
An authorization vulnerability exists in macOS Tahoe and watchOS due to improper state management. A local malicious application can exploit this flaw to bypass intended permission restrictions and access sensitive user data. The issue was addressed in macOS Tahoe 26.6 and watchOS 26.6 by implementing improved state management logic. Attackers require the ability to run code on the target device (e.g., via a malicious app) to exploit this vulnerability.
Affected products
- Apple macOS Tahoe before 26.6
- Apple watchOS before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched