Apple macOS Privacy Bypass Vulnerability in CoreServices

Vulnerability

A logic issue allowing a malicious app to access sensitive user data has been identified in the CoreServices component of Apple macOS. This vulnerability affects several different versions and was addressed with improved validation. The issue is present in macOS Sequoia 15.7, macOS Sonoma 14.8, and macOS Tahoe 26.

Impact

Exploitation of this vulnerability may lead to unauthorized access to sensitive user data.

Added: May 26, 2026, 11:54 PM
Updated: May 26, 2026, 11:54 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.2
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.