3 Sources
[1]
macOS Spotlight Vulnerability Discovered by Microsoft
Microsoft Threat Intelligence found a Spotlight-related vulnerability that could allow attackers to steal private file data, outlining the issue in a blog post today. Microsoft's threat team is calling the exploit "Sploitlight" because it uses Spotlight plugins. According to Microsoft, the
[2]
Microsoft calls out Apple Intelligence AI security flaw which could have let hackers steal private data
Microsoft has revealed details of a security vulnerability in macOS which allowed threat actors to steal sensitive information from the Apple Intelligence AI tool. In a blog post, Microsoft said it found a bug that bypasses Transparency, Consent, and Control (TCC) mechanisms found on macOS
[3]
Microsoft finds a major privacy flaw in Apple's Spotlight search
The exploit leveraged Spotlight search plugins to circumvent Apple's Transparency, Consent, and Control (TCC) framework, potentially exposing data cached by Apple Intelligence. Microsoft Threat Intelligence identified a Spotlight-related vulnerability, dubbed "Sploitlight," a Transparency,
Share
Copy Link
Microsoft's Threat Intelligence team discovered a significant security flaw in Apple's macOS Spotlight search, potentially exposing sensitive AI-cached data. The vulnerability, dubbed "Sploitlight," has since been patched by Apple.
Microsoft's Threat Intelligence team has discovered a significant security vulnerability in Apple's macOS operating system, potentially exposing sensitive data cached by Apple Intelligence AI. The vulnerability, dubbed "Sploitlight," exploits Spotlight search plugins to bypass Apple's Transparency, Consent, and Control (TCC) framework
1
.
Source: MacRumors
The "Sploitlight" exploit, tracked as CVE-2025-31199, allows attackers to circumvent TCC mechanisms designed to restrict access to sensitive user data and system features. By manipulating Spotlight plugins, which are used to index files for macOS search, attackers could potentially access and exfiltrate private information without requiring TCC permissions
2
.The vulnerability could have allowed unauthorized access to a wide range of sensitive information cached by Apple Intelligence, including:
Microsoft researchers noted that the implications of this vulnerability are more severe than previous TCC bypasses due to its ability to extract and leak sensitive information
3
.
Source: TechRadar
The vulnerability's impact is further amplified by the remote linking capability between iCloud accounts. An attacker with access to a user's macOS device could potentially exploit the vulnerability to determine remote information of other devices linked to the same iCloud account
2
.Related Stories
Upon receiving details of the bypass from Microsoft, Apple swiftly addressed the issue in macOS 15.4 and iOS 15.4 updates, released on March 31. The vulnerability was patched before it could be actively exploited
1
.Apple's security support document for the update stated that the problem was addressed through improved data redaction. Additionally, Apple fixed two other vulnerabilities credited to Microsoft by enhancing symlink validation and improving state management
3
.
Source: Dataconomy
Microsoft has implemented additional security measures in response to this discovery. Defender for Endpoint now detects "suspicious" .mdimporter installations and unusual indexing of sensitive directories
2
.This incident highlights the ongoing collaboration between tech giants in identifying and addressing critical security vulnerabilities, ultimately enhancing the safety of users' data across platforms.
Summarized by
Navi
[2]
15 Jun 2026•Technology

12 Jun 2025•Technology

23 Aug 2025•Technology

1
Technology

2
Technology

3
Policy and Regulation
