Executive brief
A security vulnerability in macOS Tahoe could allow a malicious application to bypass sandbox restrictions and access sensitive user data. This issue affects the privacy of personal information stored on the device. Users should update to macOS Tahoe 26.6 to resolve this issue.
Technical details
An access issue existed in macOS Tahoe prior to version 26.6 where the application sandbox did not sufficiently restrict access to certain sensitive data locations. A malicious application, if installed and executed by a user, could potentially bypass these sandbox boundaries to read sensitive user information. Apple addressed this vulnerability by implementing additional sandbox restrictions. The fix is available in macOS Tahoe 26.6.
Affected products
- Apple macOS Tahoe before 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: patched