Executive brief
An authorization issue in macOS could allow an individual with physical access to a locked computer to view sensitive user information. This vulnerability affects several versions of the macOS operating system used on Apple laptops and desktops. Exploitation requires the attacker to be physically present at the device while it is in a locked state. Apple has released software updates to address this issue by improving how the system manages its internal state.
Technical details
An authorization vulnerability exists in macOS Sequoia, Sonoma, and Tahoe due to improper state management. The flaw allows a physically present attacker to bypass certain authorization checks on a locked device to access sensitive user data. The root cause was identified as an issue in state management, which Apple addressed in the latest security updates. The attack requires physical access to the target hardware and does not require prior authentication. Patches are available in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Affected products
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Sonoma Before 14.8.8
- Apple macOS Tahoe Before 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: disclosed
- 2026-07-27: patched