Apple macOS Symbolic Link Handling Race Condition Vulnerability Allowing Unauthorized Contacts Access

Vulnerability

A race condition vulnerability has been identified in the handling of symbolic links within the Sync Services component of macOS. This issue allows an application to access Contacts data without the user's consent. The vulnerability is present in multiple macOS versions, including Sequoia 15.7.6, Sonoma 14.8.6, and Tahoe 26.4.

Impact

Exploitation of this vulnerability could lead to unauthorized access to Contacts data.

Remediation

Users can update to macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, or macOS Tahoe 26.5 to address this vulnerability.

Added: May 11, 2026, 10:02 PM
Updated: May 11, 2026, 10:02 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
3.8
remediation
7.7
relevance
8.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.