HomeSecuritySploitlight vulnerability in macOS allows theft of personal data

Sploitlight vulnerability in macOS allows theft of personal data

The serious Sploitlight in macOS allows attackers to bypass Transparency, Consent, and Control (TCC) mechanisms, gaining access to sensitive user data, such as files from protected folders and temporary Apple Intelligence.

See also: North Korean hackers use new macOS malware NimDoor

macOS Sploitlight vulnerability

The Sploitlight vulnerability exploits Spotlight plugins to gain access to normally protected information without user consent, posing a serious privacy risk to macOS users. According to the Microsoft Threat Intelligence, the vulnerability exploits Spotlight importers – plugins with the .mdimporter that help index system content for use in search functionality. These plugins operate through the mds and mdworker, which have privileged access to sensitive files for indexing purposes.

However, researchers discovered that attackers can tamper with these plugins to extract protected data.

The attack process involves modifying the Info.plist and schema.xml of a plugin to declare the desired file types in UTI (Uniform Type Identifier) ​​format.

Attackers can then copy the unsigned bundle to the ~/Library/Spotlight and use commands such as mdimport -r to force Spotlight to load the malicious add-on.

See also: BlueNoroff distributes MacOS malware via deepfake videos in Zoom meetings

The exploit records file contents in chunks in the unified log, allowing the extraction of sensitive data via the log tool.

Sploitlight vulnerability in macOS allows theft of personal data
Sploitlight vulnerability in macOS allows theft of personal data

Notably, the calling application does not require TCC privileges, as the indexing is performed by the mdworker process, effectively bypassing Apple's security system . The uttype utility can determine file types even without TCC access, making the attack even more flexible.

The impacts of the vulnerability are not limited to simple file access, but also extend to temporary data of the Apple Intelligence feature that are stored in protected folders, such as Pictures.

Attackers can extract highly sensitive information from databases like Photos.sqlite, including precise GPS coordinates, facial recognition data, photo metadata, search history, and user preferences.

The breach is made even more worrisome by the iCloud account, as attackers who gain access to one macOS device could potentially collect information from other devices connected to the same iCloud account. This includes face tags and metadata that is synced between Apple devices.

See also: Apple's iOS Activation Vulnerability Allows XML Payload Injection

Apple addressed this vulnerability, now tracked as CVE-2025-31199, through security updates for macOS Sequoia released on March 31, 2025.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS