Moneycontrol
HomeTechnologyMicrosoft reveals major macOS privacy flaw ‘that could expose Apple Intelligence data
Trending Topics

Microsoft reveals major macOS privacy flaw ‘that could expose Apple Intelligence data

The exploit worked by dropping malicious Spotlight plugins into user-writable directories. Spotlight would automatically index these plugins and, crucially, execute them without user interaction.

July 29, 2025 / 12:41 IST
Story continues below Advertisement

macOS

Microsoft has disclosed a severe macOS vulnerability that allowed malicious apps to bypass Apple’s privacy safeguards and access highly sensitive data—including metadata from Apple Intelligence. Dubbed “SploitLight,” the flaw took advantage of how Spotlight, macOS’s built-in search tool, indexes plugin data.

The exploit worked by dropping malicious Spotlight plugins into user-writable directories. Spotlight would automatically index these plugins and, crucially, execute them without user interaction. This allowed the attacker to bypass Apple’s Transparency, Consent, and Control (TCC) framework, which normally blocks unauthorised access to protected files like those in the Downloads folder or Safari cache.

Story continues below Advertisement

But the bigger concern lies in what Microsoft uncovered next: attackers could also extract metadata cached by Apple Intelligence—Apple’s newly introduced AI system—such as photo and video tags, precise location data, face and person recognition info, search history, and user preferences. Microsoft noted that this sensitive metadata, if exfiltrated, could potentially map out a user’s habits and movements.

To make matters worse, the exploit could extend its reach to other Apple devices connected to the same iCloud account. By linking cached data across iCloud, an attacker could infer activity on iPhones, iPads, or other Macs tied to the victim’s profile.