E
Microsoft uncovered a security flaw affecting macOS’s Spotlight.
The vulnerability (CVE-2025-31199), which Apple patched in a March 31st update, could give bad actors access to files inside a device’s Downloads folder and data cached by Apple Intelligence. That includes geolocation data, media metadata, and facial recognition info, according to a report from Microsoft Threat Intelligence.
Security researchers discovered the flaw after using Spotlight plugins to bypass a security feature made to prevent third-party services from gaining access to user data.
Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.
Loading comments
Getting the conversation ready...
Most Popular
Most Popular
- It’s not just LG. Every TV company is spying on you
- Gemini went rogue, hacked three companies, and Google hid it
- OpenAI and Microsoft knew they were starting a ‘doom loop’ for the web
- The 2.5-hour AI-generated Odyssey movie is 2.5 hours too long
- Meta’s Muse is creepy, but maybe not for the reasons you think











