Executive brief
A security vulnerability in Apple's macOS and tvOS operating systems could allow a malicious application to access sensitive user data. This occurs due to a timing issue where the system fails to properly validate data access requests. Users should update to the latest software versions to protect their personal information from unauthorized access by third-party apps.
Technical details
A race condition vulnerability exists in macOS (Sequoia, Sonoma, Tahoe) and tvOS. The flaw was addressed by implementing additional validation logic to handle concurrent processes correctly. An attacker could exploit this race condition via a malicious application installed on the device to bypass security checks and access sensitive user data. The vulnerability is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, and tvOS 26.6.
Affected products
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Sonoma Before 14.8.8
- Apple macOS Tahoe Before 26.6
- Apple tvOS Before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched