Handpicked products, unbeatable prices — shop with confidence at CannonEdge

Microsoft Uncovers Security Flaw In macOS Spotlight That Could Leak Private Data

Microsoft’s Threat Intelligence team has identified a now-fixed security vulnerability in Apple’s macOS Spotlight search tool that could have allowed unauthorized access to sensitive user data. The issue, internally dubbed “Sploitlight”, stemmed from how Spotlight handled plugin files and potentially bypassed Apple’s privacy protection framework known as Transparency, Consent, and Control (TCC).

The flaw made it possible for attackers to exploit Spotlight’s plugin system—components that normally help index app content for search and are confined within a sandbox environment. However, Microsoft’s researchers discovered a method to manipulate these plugins to gain access to cached data generated by Apple’s AI features.

If exploited, the vulnerability could have exposed a wide range of private information, including:

  • Precise location data

  • Photo and video metadata

  • Facial recognition data from the Photos app

  • Search history

  • Summaries generated by AI tools, such as email content

  • User preferences and settings

Despite the serious implications, Microsoft confirmed that the vulnerability was not actively exploited. Following responsible disclosure practices, the company reported its findings to Apple, which quickly addressed the issue.

Apple released a fix as part of macOS 15.4 and iOS 18.4, both rolled out on March 31. According to Apple’s security documentation, the patch involved improving how the system handles certain types of data, helping to ensure stricter control over plugin behavior. Alongside the Spotlight fix, Apple also resolved two additional vulnerabilities reported by Microsoft—one related to symbolic link validation and another involving system state management.

This incident underscores the importance of cross-company collaboration in addressing emerging security threats, especially as platforms continue to integrate AI and machine learning features. It also highlights the value of regular system updates, as many vulnerabilities are addressed quietly behind the scenes.

For end users, no action is needed beyond ensuring that devices are up to date. The issue has been resolved, and Apple’s rapid response prevented the vulnerability from being weaponized in real-world attacks.

Filed in Apple >Computers. Read more about , , , , and .

Trending Products

- 27% ANTEC NX200M RGB, Large Mesh Front ...
Original price was: $75.34.Current price is: $54.99.

ANTEC NX200M RGB, Large Mesh Front ...

0
Add to compare
- 24% HP 330 Wireless Keyboard and Mouse ...
Original price was: $32.99.Current price is: $24.99.

HP 330 Wireless Keyboard and Mouse ...

0
Add to compare
- 37% NZXT H9 Flow Dual-Chamber ATX Mid-T...
Original price was: $252.75.Current price is: $159.97.

NZXT H9 Flow Dual-Chamber ATX Mid-T...

0
Add to compare
- 33% KEDIERS ATX PC Case,6 PWM ARGB Foll...
Original price was: $164.98.Current price is: $109.99.

KEDIERS ATX PC Case,6 PWM ARGB Foll...

0
Add to compare
- 10% LG FHD 32-Inch Computer Monitor 32M...
Original price was: $199.99.Current price is: $179.99.

LG FHD 32-Inch Computer Monitor 32M...

0
Add to compare
- 41% SAMSUNG 27″ CF39 Collection F...
Original price was: $287.28.Current price is: $169.99.

SAMSUNG 27″ CF39 Collection F...

0
Add to compare
- 34% Dell SE2422HX Monitor – 24 in...
Original price was: $182.38.Current price is: $119.99.

Dell SE2422HX Monitor – 24 in...

0
Add to compare
- 36% Aircove Go | Portable Wi-Fi 6 VPN R...
Original price was: $266.74.Current price is: $169.90.

Aircove Go | Portable Wi-Fi 6 VPN R...

0
Add to compare
- 40% Motorola MG7550 – Modem with ...
Original price was: $200.32.Current price is: $119.95.

Motorola MG7550 – Modem with ...

0
Add to compare
- 37% Cudy TR3000 Pocket-Sized Wi-Fi 6 Wi...
Original price was: $142.94.Current price is: $89.90.

Cudy TR3000 Pocket-Sized Wi-Fi 6 Wi...

0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

TheCannonEdge
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart