Executive brief
The Accessibility framework in macOS handles system features that assist users with disabilities. A vulnerability allows an app to access sensitive user data without proper authorization. This could expose personal information to malicious applications.
Technical details
A data protection issue in the macOS Accessibility framework allows unauthorized access to sensitive user data. The vulnerability is rooted in insufficient data isolation; an app may bypass access controls and read protected user information. The attack requires the malicious app to be installed and running on the system (local attack vector). An attacker can leverage this to exfiltrate personal data such as credentials, personal identifiers, or communication content. The vulnerability is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 with improved data protection mechanisms.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched