logo

Microsoft spotlights Apple bug patched in March as SharePoint exploits continue

ID: e2b29e43-6f1e-5598-a915-0715c5605804

STIX ID: report--e2b29e43-6f1e-5598-a915-0715c5605804

Feed Name: The Register (Security)

Threat Score
60/100

Date Published: 2025-07-28

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Microsoft Threat Intelligence disclosed a now-fixed macOS Sequoia vulnerability (CVE-2025-31199, "Sploitlight") that abused Spotlight importers to bypass the TCC privacy framework and potentially exfiltrate Apple Intelligence cached data—such as precise geolocation, photo/video metadata, face/person recognition data, and search history—posing risks like stalking and cross-device data exposure; Apple released a patch in March.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.