macOS 15 - Sequoia

The macOS system must disable sending Siri and Dictation information to Apple

STIG ID: APPL-15-002210 | SRG: SRG-OS-000095-GPOS-00049 | Severity: Medium | CCI: CCI-000381 | Vulnerability ID: V-268527

Description

The ability for Apple to store and review audio of Siri and Dictation interactions must be disabled.The information system must be configured to provide only essential capabilities. Disabling the submission of Siri and Dictation information will mitigate the risk of unwanted data being sent to Apple.

Check

C-268527r1034521_chk

Verify the macOS system is configured to disable sending Siri and Dictation information to Apple with the following command:/usr/bin/osascript -l JavaScript << EOS$.NSUserDefaults.alloc.initWithSuiteName('com.apple.assistant.support')\.objectForKey('Siri Data Sharing Opt-In Status').jsEOSIf the result is not "2", this is a finding.

Fix

F-72458r1034520_fix

Configure the macOS system to disable sending Siri and Dictation information to Apple by installing the "com.apple.assistant.support" configuration profile.