Your same argument would stand without modification for reading all data from the keychain, accessing files saved by other applications, using your location, or any other things that require permissions: clearly, then, it is wrong on the face of it, because Apple has simply failed to secure a wide class of things from these processes. It honestly doesn't matter whether there is an "API" for it at the C or Objective-C layers, and that is a red herring: the issue is that there is an IPC layer somewhere (whether a Mach server or a file on disk) that exposes an API by which this data can be obtained by this process.