Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

macOS Flaw Allows TCC Bypass, Exposing Sensitive User Information

## Cybersecurity: Apple Accessibility Framework Vulnerability

Cybersecurity: Apple Accessibility Framework Vulnerability

A critical vulnerability has been identified in Apple's accessibility framework, known as a Transparency, Consent, and Control (TCC) bypass. This flaw exposes sensitive user data and permits unauthorized execution of AppleScript.

The vulnerability, designated as CVE-2025-43530, affects the ScreenReader framework. The MIG service within this framework allows attackers to execute unauthorized AppleScript commands and send AppleEvents to protected processes without user consent.

The issue stems from the private API in ScreenReader.framework, specifically within the com.Apple.scrod MIG service. This service is initiated from system configuration files.

The vulnerability is due to a flawed trust validation mechanism in the service routine __SCROXGetValueForKeyWithObject , which incorrectly determines whether an XPC client can execute privileged operations. Two primary security issues have been identified:

A critical vulnerability has been identified in Apple's accessibility framework, known as a Transparency, Consent, and Control (TCC) bypass.
Hazel Caldwell · Thehackingpost

The vulnerability accepts any process signed by Apple as trusted, allowing attackers to inject malicious code without root privileges into Apple-signed executables like /usr/libexec/ssh-apple-pkcs11 . The service uses the SecStaticCodeCreateWithPath API for client authentication, rather than the client’s audit token, introducing a Time-of-Check-Time-of-Use (TOCTOU) attack window. This enables manipulation of process identity between validation and execution.

Exploiting this vulnerability allows attackers to execute arbitrary AppleScript files and send AppleEvents to any process, including Finder, bypassing TCC protections entirely.

The attack requires only local access, making it particularly risky for multi-user systems. Researchers have identified at least nine additional MIG service routines with similar vulnerable trust-checking logic, potentially leading to further exploitation paths. Affected services include __XRegisterWithServer , __XSendEvent , and __XPerformAction .

Advertisement

Apple has addressed this vulnerability in macOS 26.2 by restricting trust to processes explicitly holding the "com.apple.private.accessibility.scrod" entitlement. The updated validation now utilizes the client’s audit token, eliminating the TOCTOU window.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories