Executive brief
The Apple Account framework in macOS Tahoe contains a race condition that could allow a malicious app to access sensitive user data. This vulnerability affects the authentication and account management system used across macOS, potentially exposing user credentials, personal information, or account details. The issue has been patched in macOS Tahoe 26.6 with improved state handling.
Technical details
A race condition was identified in the Apple Account framework where concurrent operations on account state could lead to authorization bypass conditions. The vulnerability exists due to insufficient synchronization when handling account state transitions, allowing an app to access protected user data without proper authorization checks. The attack requires local execution context (sandboxed app) but no special user interaction beyond normal app operation. An attacker could leverage this to exfiltrate sensitive account information or session tokens. The vulnerability has been fixed in macOS Tahoe 26.6 with improved state handling mechanisms.
Affected products
- Apple macOS Tahoe prior to 26.6
Timeline
- 2026-09-14: disclosed
- 2026-07-27: patched: Fixed in macOS Tahoe 26.6