macOS Spotlight Vulnerability Discovered by Microsoft - MacRumors
Skip to Content

macOS Spotlight Vulnerability Discovered by Microsoft

Microsoft Threat Intelligence found a Spotlight-related vulnerability that could allow attackers to steal private file data, outlining the issue in a blog post today. Microsoft's threat team is calling the exploit "Sploitlight" because it uses Spotlight plugins.

bug security vulnerability issue fix larry
According to Microsoft, the vulnerability is a Transparency, Consent, and Control (TCC) bypass that can leak sensitive info cached by Apple Intelligence. Attackers could have used it to get precise location data, photo and video metadata, face recognition data from the Photo Library, search history, AI email summaries, user preferences, and more.

TCC is designed to keep apps from accessing personal information without user consent. Spotlight plugins that allow app files to appear in search are sandboxed by Apple and heavily restricted from accessing sensitive files, but Microsoft found a way around that. Microsoft researchers tweaked the app bundles that Spotlight pulls in, leaking file contents.

Microsoft shared details of the bypass with Apple, and Apple addressed the issue in macOS 15.4 and iOS 15.4, updates that came out on March 31. The vulnerability was never actively exploited, because Apple was able to fix it before it was disclosed.

Apple's security support document for the update said that the problem was addressed through improved data redaction. Apple fixed two other vulnerabilities that were credited to Microsoft at the same time with improved validation of symlinks and improved state management.

Full information on how the exploit worked can be found on Microsoft's website.

Popular Stories

General macOS Mail Feature

Apple Patches Hide My Email Flaw More Than a Year After It Was Reported

Tuesday July 21, 2026 10:10 am PDT by
Apple addressed a vulnerability in Hide My Email that exposed a user's real email address, reports 404 Media. Apple told the site the issue was fully fixed in a patch released on July 3. The Hide My Email vulnerability was brought to Apple's attention in June 2025, but the company did not fix it until 404 Media publicized the bug in early July. EasyOptOuts co-founder Tyler Murphy, who...
apple lock security bug vulnerability fix privacy

Update Now: iOS 26.6 and macOS Tahoe 26.6 Patch Hundreds of Security Flaws

Monday July 27, 2026 11:55 am PDT by
Apple today released iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6, all of which have a long list of security fixes. iOS 26.6 and iPadOS 26.6 address almost 90 security vulnerabilities affecting everything from the App Store to the Neural Engine. Multiple kernel and WebKit vulnerabilities were fixed, along with problems affecting Wi-Fi, Siri, and the iPhone's image processing. Details on...
Apple Event Logo

Apple Working on All-New Operating System

Wednesday July 29, 2026 11:39 am PDT by
Apple is developing an all-new operating system that is essentially a mix of tvOS, watchOS, and iOS, according to Bloomberg's Mark Gurman. In a report this week, he said the operating system will feature a grid of icons, widgets, and apps, along with customizable clock faces. The new software platform is intended for Apple's long-rumored smart home hub. With built-in facial recognition,...

Top Rated Comments

13 months ago
I don't often complain about headlines here, but unless I'm missing something, this one strikes me as misleading. I read it and the article thinking that this was a new, unaddressed vulnerability, only to find that it was taken care of by Apple a few months ago.
Score: 22 Votes (Like | Disagree)
carswell Avatar
13 months ago
Another reason to turn off Apple "Intelligence"! /s
Score: 14 Votes (Like | Disagree)
13 months ago
Nice to know, but a click-baity headline. Skimmers will assume this is active.
Score: 11 Votes (Like | Disagree)
johannnn Avatar
13 months ago
What's the news here? Every .x update includes security patches. And this was a .x release back in March lol
Score: 10 Votes (Like | Disagree)
urmaster Avatar
13 months ago

I don't often complain about headlines here, but unless I'm missing something, this one strikes me as misleading. I read it and the article thinking that this was a new, unaddressed vulnerability, only to find that it was taken care of by Apple a few months ago.
I guess Microsoft followed responsible disclosure methods so it's quite right that we're only hearing about it after the patch is widely deployed.
Score: 7 Votes (Like | Disagree)
13 months ago
Not to worry, everyone, because Apple was able to fix this before it ever affected a single customer. Apple was able to do this because of their best-in-class privacy, which only Apple can provide!
Score: 5 Votes (Like | Disagree)