Apple Contacts Privacy Vulnerability in macOS Sequoia

Vulnerability

A permissions vulnerability in the Contacts app on macOS Sequoia 15.1 allows applications to access contact information without user consent. This issue was addressed by implementing additional restrictions. The vulnerability was reported by Csaba Fitzl (@theevilbit) of Kandji.

Impact

Exploitation of this vulnerability could lead to unauthorized access to a user's contact information.

Added: Apr 2, 2026, 9:45 PM
Updated: Apr 2, 2026, 9:45 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.2
remediation
7.7
relevance
5.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.