logo

macOS Flaw Allows TCC Bypass, Exposing Sensitive User Information

ID: 71d32c71-8647-5b21-9637-4f415470aa00

STIX ID: report--71d32c71-8647-5b21-9637-4f415470aa00

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-06

Date Updated: 2026-04-22

Author: Divya

...
...

Researchers disclosed CVE-2025-43530, a critical TCC bypass in macOS ScreenReader.framework (com.Apple.scrod) that lets local attackers execute arbitrary AppleScript and send AppleEvents to protected processes by abusing flawed trust checks (accepting any Apple-signed binary and using SecStaticCodeCreateWithPath, creating a TOCTOU opportunity); multiple MIG routines share the same logic and Apple patched the issue in macOS 26.2 by requiring a specific entitlement and using the client's audit token.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.