Executive brief
macOS's Accessibility framework controls how applications interact with system features like text and object manipulation. A flaw allows malicious applications to access sensitive user data that should be protected. This could enable data theft, including personal information or credentials, without the user's knowledge or consent.
Technical details
A permissions issue in the Accessibility framework was exploited to bypass data protection controls. The vulnerability allows applications to access sensitive user information that should be restricted by macOS's privacy model. The attack requires local execution (app installed on the system), no user interaction beyond normal app usage. An attacker can craft a malicious app to extract protected personal data. The issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 through improved data protection mechanisms.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7