Impact
The vulnerability is caused by insufficient permission checks that allow an application to read protected user data. The weakness is a typical failure of authorization controls. An attacker who can install or run code on the affected macOS machine could exploit the flaw to read data normally restricted by the operating system, potentially exposing personal information, credentials, or other sensitive content.
Affected Systems
Apple macOS versions released before Sequoia 15.3 are affected. Updating to macOS Sequoia 15.3 or later removes the flaw.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog. Likely attack vectors involve a local attacker or a malicious application that bypasses normal permission boundaries. No remote code execution capability is disclosed.
OpenCVE Enrichment
EUVD