Description
This issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A person with physical access to a locked device may be able to access contacts and photos.
Published: 2026-07-27
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the lock screen restrictions of macOS allows a user who physically holds a locked device to retrieve the device’s contacts and photos. The flaw is an Authentication and Authorization Control weakness (CWE-287) and does not involve remote exploitation; it arises solely from insufficient enforcement of access controls once the device is locked. The primary consequence is the loss of confidentiality for user data that should be protected while the device is secured. The likely attack vector is an attacker physically in possession of a locked device, as the weakness only triggers when the device is locked.

Affected Systems

The issue affects Apple macOS devices for which the fix is provided in macOS Sequoia 15.7.8 and macOS Tahoe 26.6. Versions prior to these releases are considered vulnerable; however, no explicit list of affected versions is supplied by the CNA.

Risk and Exploitability

The vulnerability is a local, physical access exploit that does not involve remote attack surfaces. The EPSS score of < 1% indicates a very low exploitation probability, though the weakness remains actionable. It is inferred that the exploitation requires physical possession of a locked Mac running an affected macOS version, because the flaw only triggers while the device is locked. The vulnerability is not listed in the CISA KEV catalog. However, those who can obtain physical possession of an affected device can read contacts and photos, heightening the risk for individuals who leave a Mac unattended.

Generated by OpenCVE AI on August 4, 2026 at 23:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch that addresses the Authentication and Authorization Control flaw (CWE-287) by updating macOS to at least Sequoia 15.7.8 or Tahoe 26.6.
  • If an update is not immediately possible, restrict physical access to the device and keep it locked when unattended.
  • Enable FileVault full-disk encryption to protect data even if the lock screen controls are bypassed.

Generated by OpenCVE AI on August 4, 2026 at 23:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Physical Access Exploitation of Lock Screen Reveals Contacts and Photos on macOS

Mon, 03 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Physical Access to Locked macOS Device Exposes Contacts and Photos
Weaknesses CWE-284
CWE-522

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Physical Access to Locked macOS Device Exposes Contacts and Photos
Weaknesses CWE-284
CWE-287
CWE-522
Metrics cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A person with physical access to a locked device may be able to access contacts and photos.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:37:05.070Z

Reserved: 2026-07-20T18:10:18.985Z

Link: CVE-2026-64745

cve-icon Vulnrichment

Updated: 2026-07-28T14:36:55.435Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:13.377

Modified: 2026-07-28T18:44:46.630

Link: CVE-2026-64745

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T00:00:03Z

Weaknesses