Executive brief
A security issue in macOS could allow a malicious application to bypass privacy protections and access sensitive user data. This affects computers running macOS Sequoia, Sonoma, and Tahoe. Apple has released software updates to address this logic error by improving internal security checks. Users should update their devices to the latest available version to protect their personal information.
Technical details
A logic vulnerability exists in macOS Sequoia, Sonoma, and Tahoe that could allow a locally installed application to bypass security restrictions and access sensitive user data. The root cause is a logic error in how the operating system validates application permissions or data access requests. Apple addressed this issue by implementing improved validation checks within the affected components. The vulnerability is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Exploitation requires a malicious app to be running on the target system.
Affected products
- Apple macOS Sequoia before 15.7.8
- Apple macOS Sonoma before 14.8.8
- Apple macOS Tahoe before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory
- 2026-07-27: patched