Executive brief
A security issue in macOS could allow a malicious application to bypass access restrictions and view sensitive user data. This affects computers running macOS Sonoma and macOS Tahoe. Apple has released software updates to address this by improving how the system restricts data access.
Technical details
An access control vulnerability exists in macOS Sonoma and macOS Tahoe where improved access restrictions were required to prevent unauthorized data retrieval. A malicious application installed on the system could exploit this flaw to bypass intended privacy controls and access sensitive user information. The vulnerability was addressed by Apple through improved access restrictions in macOS Sonoma 14.8.8 and macOS Tahoe 26.6. The attack vector is local, requiring a malicious app to be present on the target device.
Affected products
- Apple macOS Sonoma < 14.8.8
- Apple macOS Tahoe < 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: patched