Impact
A vulnerability in the lock screen restrictions of macOS allows a user who physically holds a locked device to retrieve the device’s contacts and photos. The flaw is an Authentication and Authorization Control weakness (CWE-287) and does not involve remote exploitation; it arises solely from insufficient enforcement of access controls once the device is locked. The primary consequence is the loss of confidentiality for user data that should be protected while the device is secured. The likely attack vector is an attacker physically in possession of a locked device, as the weakness only triggers when the device is locked.
Affected Systems
The issue affects Apple macOS devices for which the fix is provided in macOS Sequoia 15.7.8 and macOS Tahoe 26.6. Versions prior to these releases are considered vulnerable; however, no explicit list of affected versions is supplied by the CNA.
Risk and Exploitability
The vulnerability is a local, physical access exploit that does not involve remote attack surfaces. The EPSS score of < 1% indicates a very low exploitation probability, though the weakness remains actionable. It is inferred that the exploitation requires physical possession of a locked Mac running an affected macOS version, because the flaw only triggers while the device is locked. The vulnerability is not listed in the CISA KEV catalog. However, those who can obtain physical possession of an affected device can read contacts and photos, heightening the risk for individuals who leave a Mac unattended.
OpenCVE Enrichment