Executive brief
A security issue in the macOS lock screen could allow an unauthorized person with physical access to a locked computer to view private information. Specifically, an attacker could bypass the lock screen to access a user's contacts and photos. This vulnerability has been addressed in the latest macOS updates by implementing stricter restrictions on lock screen functionality.
Technical details
A lock screen bypass vulnerability exists in macOS Sequoia and macOS Tahoe. The flaw allows an attacker with physical access to a locked device to circumvent security controls and access sensitive user data, including the Contacts and Photos databases. Apple addressed the issue by implementing additional restrictions on the lock screen to prevent unauthorized data access. The vulnerability is fixed in macOS Sequoia 15.7.8 and macOS Tahoe 26.6.
Affected products
- Apple macOS Sequoia < 15.7.8
- Apple macOS Tahoe < 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory
- 2026-07-27: patched