TTB White LOGO TB
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Trending
How Anthropic’s Weekly Rate Limits Will Affect Your Claude Code Access
Your Tab Overload Ends Now: Microsoft Edge’s Copilot Does the Work For You
Why Buy Bookshelves When You Can Build Portals? Calibre Awaits
Apple Seals TCC Bypass in Spotlight That Exposed Private AI Caches
Chrome’s New AI Tool Tells You Which Online Stores to Trust Instantly
Tuesday, Jul 29, 2025
The Tech BasicThe Tech Basic
Font ResizerAa
Search
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Follow US
Apple
The Tech Basic > News > Apple Seals TCC Bypass in Spotlight That Exposed Private AI Caches
News

Apple Seals TCC Bypass in Spotlight That Exposed Private AI Caches

Salman Akhtar
Last updated: 29 July 2025 11:54
Salman Akhtar
Share
Image Source: Jamf
SHARE

Apple has released a security update that stops a macOS flaw capable of exposing private files protected by Transparency Consent and Control (TCC). The vulnerability nicknamed Sploitlight exploited Spotlight importers to bypass TCC rules and leak data such as photo metadata, precise location history, and Apple Intelligence caches.

Contents
What is SploitlightRisks to Apple Intelligence and iCloud syncApple’s response and fixHow to protect your data

What is Sploitlight

Spotlight indexes files on a Mac to support fast searches. It uses small components called importers to read file contents and return metadata. Normally, these importers run in a sandbox and respect TCC restrictions that guard folders like Downloads, Desktop, and Pictures. Microsoft Threat Intelligence discovered that a malicious importer could log and exfiltrate file contents by writing them to system logs, then read them back without requiring elevated privileges.

Apple
Image Source: Hackread

Risks to Apple Intelligence and iCloud sync

Sploitlight could access more than static files. It also targeted caches used by Apple Intelligence, including note summaries, search preferences, and face recognition tags. Because iCloud sync links Macs, iPhones, and iPads, data stolen from one device might reveal information on others. Attackers with access to a single Mac could harvest sensitive details from a user’s entire Apple ecosystem.

Apple’s response and fix

Microsoft reported the issue early in 2025. Apple addressed it on March 31 in an update to macOS Sequoia. The patch appears under CVE‑2025‑31199. Apple’s security notes explain that the fix improved data redaction and tightened how Spotlight handles plugin requests. Users running macOS Sequoia 15.4 or later have received the update automatically if they keep software updates turned on.

How to protect your data

Users should install the latest macOS updates immediately, even if no irregular activity has appeared. Do not install an unsigned Spotlight plugin or software of unknown origin that asks for access to system folders. The administrators have the possibility to check logs to detect some indications of custom importers loaded using user directories. Maintaining all the devices on the latest operating system version helps in mitigating the chances of a potential attacker using previously unpatched vulnerabilities.

Apple
Image Source: 9to5Mac

It is essential to make sure that all Apple devices connected to iCloud are safe. Any single hacked Mac may cause a wider data breach on the iPhone and iPad of a user. Check whether updates are installed successfully and activate privacy protection under System Settings on a regular basis. By blocking Sploitlight, Apple has tightened the integrity of Spotlight and has shielded the Apple Intelligence assets.

TAGGED:AIAppleiOSMicrosoft
Share This Article
Facebook Reddit Copy Link Print
Share
Salman Akhtar
By Salman Akhtar
View enlightening tech pieces written by Salman Keep up with the most recent news, advice, and trends in the field of technology.

Let's Connect

FacebookLike
XFollow
PinterestPin
InstagramFollow
Google NewsFollow
FlipboardFollow

Popular Posts

Anthropic Claude Code

How Anthropic’s Weekly Rate Limits Will Affect Your Claude Code Access

Salman Akhtar
Lifewire

Your Tab Overload Ends Now: Microsoft Edge’s Copilot Does the Work For You

Salman Akhtar
Calibre

Why Buy Bookshelves When You Can Build Portals? Calibre Awaits

Salman Akhtar
Google Chrome

Chrome’s New AI Tool Tells You Which Online Stores to Trust Instantly

Salman Akhtar

You Might Also Like

Apple AI
News

Apple’s 18-Month Race: How Foldables and AI Will Define Its Future

OpenAI
News

OpenAI CEO Altman: ChatGPT Chats Lack Therapist Privacy

Meta
News

Meta Welcomes Zhao as Visionary Lead in AI Superintelligence Division

iPhone 17 Pro
MobilesNews

iPhone 17 Pro Rumors: 8x Zoom, Pro Camera App, New Button

Social Networks

Facebook-f Twitter Instagram Pinterest Rss

Company

  • About Us
  • Our Team
  • Contact Us

Policies

  • Disclaimer
  • Privacy Policy
  • Cookies Policy
Latest
DeepSeek Boosts China’s AI Race as Washington Rolls Out New Plan
Why Meta Calls EU’s New Ad Transparency Law Impossible to Follow
Why Did Google Take a Month to Act Against Firebase-Hosted Spyware?
Apple’s Dating App Fee Showdown: Why Europe Holds All Cards
Imagination to App: How Google Opal Democratizes AI Creation Now

© 2024 The Tech Basic INC. 700 – 2 Park Avenue New York, NY.

TTB White LOGO TB
Follow US
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?