Microsoft spotlights Apple bug patched in March as SharePoint exploits continue
ID: e2b29e43-6f1e-5598-a915-0715c5605804
STIX ID: report--e2b29e43-6f1e-5598-a915-0715c5605804
Feed Name: The Register (Security)
Threat Score
Microsoft Threat Intelligence disclosed a now-fixed macOS Sequoia vulnerability (CVE-2025-31199, "Sploitlight") that abused Spotlight importers to bypass the TCC privacy framework and potentially exfiltrate Apple Intelligence cached data—such as precise geolocation, photo/video metadata, face/person recognition data, and search history—posing risks like stalking and cross-device data exposure; Apple released a patch in March.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
