Executive brief
A privacy vulnerability in macOS could allow a malicious application to access and leak sensitive user information. This issue affects the operating system used on Apple laptops and desktop computers. Exploitation could lead to the unauthorized exposure of personal data, potentially impacting user privacy and corporate data security. Apple has released software updates to address this issue by removing the sensitive data that was being exposed.
Technical details
A privacy vulnerability exists in multiple versions of macOS where sensitive user information could be leaked to local applications. The root cause is the improper handling or storage of sensitive data within the operating system, which Apple addressed by removing the data in question. An attacker would need to have a malicious application running on the target system to exploit this flaw. Successful exploitation allows the application to bypass intended privacy protections and access sensitive user data. The issue is resolved in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Affected products
- Apple macOS Sequoia before 15.7.8
- Apple macOS Sonoma before 14.8.8
- Apple macOS Tahoe before 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: disclosed