Executive brief
An authorization issue in macOS could allow a malicious application to bypass security controls and access sensitive user data. This vulnerability affects the way the operating system manages internal states, potentially leading to unauthorized information disclosure. Users should update to the latest versions of macOS to protect their private information.
Technical details
An authorization vulnerability exists in macOS Sequoia and macOS Tahoe due to flawed state management. A local application could exploit this issue to bypass intended authorization checks and gain access to sensitive user information. The vulnerability was addressed by improving state management logic within the operating system. The fix is available in macOS Sequoia 15.7.8 and macOS Tahoe 26.6.
Affected products
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Tahoe Before 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: patched