logo

Critical macOS Flaw Lets Attackers Bypass Apple Privacy Controls Without Consent

ID: 17aeefc9-89fe-5c8a-8c91-21698fb460a3

STIX ID: report--17aeefc9-89fe-5c8a-8c91-21698fb460a3

Feed Name: TechRepublic Security

Threat Score
70/100

Date Published: 2026-01-07

Date Updated: 2026-04-23

Author: Ken Underhill

...
...

A recently disclosed macOS vulnerability (CVE-2025-43530) lets attackers fully bypass the Transparency, Consent, and Control (TCC) privacy system by abusing Apple-signed accessibility components (VoiceOver) through dynamic-library injection and a TOCTOU race, enabling silent AppleScript/AppleEvent execution to access files and microphone without prompts; a patch is available (macOS 26.2), proof-of-concept code exists, and mitigations include immediate patching, restricting accessibility/automation permissions, enforcing least privilege, and monitoring for suspicious automation behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.