Executive brief
The Apple Account component in macOS and watchOS contains a flaw that allows malicious applications to leak sensitive user information. An attacker can exploit this vulnerability by deploying a malicious app that accesses private account data without proper authorization. This could lead to unauthorized disclosure of personal information such as account details or authentication tokens.
Technical details
An information disclosure vulnerability exists in the Apple Account component due to improper state management. The vulnerability allows a malicious application to bypass authorization checks and access sensitive user account information. The issue affects macOS Golden Gate 27 (Apple silicon Macs from 2020 onwards) and watchOS 27 (Apple Watch Series 9 and later). The attack requires a malicious app to be installed on the system; it does not require network access or user interaction beyond normal app usage. The vulnerability has been patched in the releases mentioned above through improved state management controls.
Affected products
- Apple macOS Golden Gate before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixed in macOS Golden Gate 27 and watchOS 27