Impact
The vulnerability allows a local application to read memory beyond intended bounds, enabling it to access sensitive location information stored within the system. The flaw corresponds to CWE‑125, a bounds reading error, and can result in the exposure of personal location data without the user’s knowledge. The incident is mitigated by improved data protection mechanisms delivered in recent macOS releases.
Affected Systems
All Apple macOS releases prior to macOS Sequoia 15.3 and macOS Sonoma 14.7.3 are affected. Users running older macOS versions may experience unintended location data exposure if they run applications that trigger the memory over‑read flaw.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate risk, and the EPSS score of less than 1% denotes a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. It can be exploited by a malicious or compromised application running locally on the target device, potentially allowing the attacker to read sensitive device location data without additional permissions.
OpenCVE Enrichment
EUVD