macOS 15 - Sequoia

The macOS system must disable sending search data from Spotlight to Apple

STIG ID: APPL-15-002024 | SRG: SRG-OS-000095-GPOS-00049 | Severity: Medium | CCI: CCI-000381 | Vulnerability ID: V-269566

Description

Sending data to Apple to help improve search must be disabled.The information system must be configured to provide only essential capabilities. Disabling the submission of search data will mitigate the risk of unwanted data being sent to Apple.

Check

C-269566r1034793_chk

Verify the macOS system is configured to disable sending search data from Spotlight with the following command:/usr/bin/osascript -l JavaScript << EOS$.NSUserDefaults.alloc.initWithSuiteName('com.apple.assistant.support')\.objectForKey('Search Queries Data Sharing Status').jsEOSIf the result is not "2", this is a finding.

Fix

F-73500r1034792_fix

Configure the macOS system to disable sending search data from Spotlight by installing the "com.apple.assistant.support" configuration profile.