Executive brief
A logic flaw in macOS allows an attacker positioned on a privileged network location to intercept and leak sensitive user information. The vulnerability affects multiple versions of Apple's desktop operating system and could expose personal data such as account details or communications passing through the network.
Technical details
The vulnerability is a logic issue in macOS network handling code that was addressed with improved validation checks. An attacker positioned on a privileged network segment (such as a compromised Wi-Fi network or network infrastructure) can exploit this flaw to leak sensitive user information. The attack vector is adjacent network access, meaning the attacker must be on the same network or a network position between the user and critical services. The vulnerability is patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched