Description
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker with physical access to a locked device may be able to view sensitive user information.
Published: 2026-07-27
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authorization flaw that allows an attacker who can physically access a locked macOS device to view sensitive information that should be protected by user credentials. The flaw is due to improper state handling during lock state transitions, which can expose the device's current session context to local processes. The impact is the potential disclosure of user data, including messages, files, and possibly login keys, which compromises confidentiality.

Affected Systems

Affected Apple macOS releases include any version prior to Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6. The issue is resolved in those builds, so systems using older releases are vulnerable. The scope is limited to physical possession of the device while it remains locked, but the information that can be obtained could be sensitive to an attacker.

Risk and Exploitability

The risk level, as evaluated by current metrics, is that exploitation requires proximity and physical access, which reduces the likelihood of widespread attacks. However, the potential for private data exposure warrants prompt remediation. As the EPSS score is less than 1% and KEV is not listed, the severity is lower compared to remote‑exploitable vulnerabilities, yet the confidentiality impact remains serious.

Generated by OpenCVE AI on August 4, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest macOS release (Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.6) as provided by Apple.
  • If an upgrade is not feasible, keep the device locked at all times and restrict physical access to trusted individuals; enable full‑disk encryption to prevent unauthorized data access even on a recovered device.
  • In environments where devices may be stolen, consider additional hardware security features such as a secure enclave or TPM to protect stored credentials from physical extraction.

Generated by OpenCVE AI on August 4, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Authorization flaw enabling physical access to view sensitive data on locked macOS devices

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Physical Access Authorization Flaw Exposes Sensitive User Data on macOS
Weaknesses CWE-284

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Physical Access Authorization Flaw Exposes Sensitive User Data on macOS
Weaknesses CWE-284
CWE-287
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker with physical access to a locked device may be able to view sensitive user information.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T15:54:54.090Z

Reserved: 2026-05-01T22:46:27.817Z

Link: CVE-2026-43766

cve-icon Vulnrichment

Updated: 2026-07-28T15:54:12.061Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:00.977

Modified: 2026-07-28T19:54:56.587

Link: CVE-2026-43766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:30:10Z

Weaknesses